UBUNTU-CVE-2021-42528
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-42528
UBUNTU-CVE-2021-42528
Summary:
Details: XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
References: https://ubuntu.com/security/CVE-2021-42528, https://helpx.adobe.com/security/products/xmpcore/apsb21-108.html, https://github.com/adobe/XMP-Toolkit-SDK/commit/16e53564ae6c2689387479c04770f492075d5b7b, https://cgit.freedesktop.org/exempi/commit/?h=adobe-sdk&id=16e53564ae6c2689387479c04770f492075d5b7b, https://ubuntu.com/security/notices/USN-5483-1, https://www.cve.org/CVERecord?id=CVE-2021-42528
Affected packages
Package
Name: exempi
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
