Mageia 2022-0236: exempi security update
Summary
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an
out-of-bounds read vulnerability that could lead to disclosure of
arbitrary memory. An attacker could leverage this vulnerability to bypass
mitigations such as ASLR. Exploitation of this issue requires user
interaction in that a victim must open a malicious file. (CVE-2021-36045)
XMP Toolkit version 2020.1 (and earlier) is affected by a memory
corruption vulnerability, potentially resulting in arbitrary code
execution in the context of the current user. User interaction is required
to exploit this vulnerability. (CVE-2021-36046)
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper
Input Validation vulnerability potentially resulting in arbitrary code
execution in the context of the current user. Exploitation requires user
interaction in that a victim must open a crafted file. (CVE-2021-36047)
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper
Input Validation vulnerability potent...
References
- https://bugs.mageia.org/show_bug.cgi?id=30557
- https://ubuntu.com/security/notices/USN-5483-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36045
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36046
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36047
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36048
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36050
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36051
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36052
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36053
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36054
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36055
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36056
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36058
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36064
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39847
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40716
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40732
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42528
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42529
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42530
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42531
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42532
Resolution
MGASA-2022-0236 - Updated exempi packages fix security vulnerability
SRPMS
- 8/core/exempi-2.5.1-2.1.mga8