An issue was discovered in Exempi before 2.4.4. The TradQT_Manager::ParseCachedBoxes function in XMPFiles/source/FormatSupport/QuickTime_Support.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .qt file.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Exempi | Exempi_project | * | 2.4.4 (excluding) |
| Red Hat Enterprise Linux 7 | RedHat | exempi-0:2.2.0-9.el7 | * |
| Exempi | Ubuntu | artful | * |
| Exempi | Ubuntu | esm-infra/xenial | * |
| Exempi | Ubuntu | trusty | * |
| Exempi | Ubuntu | upstream | * |
| Exempi | Ubuntu | xenial | * |