CVE Vulnerabilities

CVE-2021-36052

Access of Memory Location After End of Buffer

Published: Sep 01, 2021 | Modified: Oct 19, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

Weakness

The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.

Affected Software

Name Vendor Start Version End Version
Xmp_toolkit_software_development_kit Adobe * 2020.1 (including)
Exempi Ubuntu bionic *
Exempi Ubuntu esm-infra/xenial *
Exempi Ubuntu focal *
Exempi Ubuntu impish *
Exempi Ubuntu jammy *
Exempi Ubuntu upstream *

References