Bug 2231135 (CVE-2023-38210) - CVE-2023-38210 xmpcore: Uncontrolled Resource Consumption
Summary: CVE-2023-38210 xmpcore: Uncontrolled Resource Consumption
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2023-38210
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2231136 2231137
Blocks: 2231138
TreeView+ depends on / blocked
 
Reported: 2023-08-10 17:43 UTC by Pedro Sampaio
Modified: 2023-08-14 22:54 UTC (History)
17 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
An uncontrolled resource consumption flaw was found in the Adobe XMP Toolkit. This issue may allow an unauthenticated attacker to send a malicious file, which when opened by a user, could lead to an application denial of service.
Clone Of:
Environment:
Last Closed: 2023-08-14 19:50:18 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2023-08-10 17:43:47 UTC
Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

References:

https://helpx.adobe.com/security/products/xmpcore/apsb23-45.html

Comment 1 Pedro Sampaio 2023-08-10 17:44:21 UTC
Created xmpcore tracking bugs for this issue:

Affects: epel-7 [bug 2231137]
Affects: fedora-all [bug 2231136]


Note You need to log in before you can comment on or make changes to this bug.