Red Hat Bugzilla – Bug 1558715
CVE-2017-18238 exempi: Infinite loop TradQT_Manager::ParseCachedBoxes function in XMPFiles/source/FormatSupport/QuickTime_Support.cpp
Last modified: 2018-04-30 14:12:43 EDT
An issue was discovered in Exempi before 2.4.4. The TradQT_Manager::ParseCachedBoxes function in XMPFiles/source/FormatSupport/QuickTime_Support.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .qt file. Upstream bug: https://bugs.freedesktop.org/show_bug.cgi?id=102483 Upstream patch: https://cgit.freedesktop.org/exempi/commit/?id=886cd1d2314755adb1f4cdb99c16ff00830f0331
Created exempi tracking bugs for this issue: Affects: fedora-all [bug 1558717]
Statement: This issue did not affect the versions of Exempi as shipped with Red Hat Enterprise Linux 6 as they did not include the vulnerable code.