CVE Vulnerabilities

CVE-2021-36057

Write-what-where Condition

Published: Sep 01, 2021 | Modified: Feb 16, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the applications memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user.

Weakness

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Affected Software

Name Vendor Start Version End Version
Xmp_toolkit_software_development_kit Adobe * 2020.1 (including)
Exempi Ubuntu bionic *
Exempi Ubuntu esm-infra/xenial *
Exempi Ubuntu focal *
Exempi Ubuntu impish *
Exempi Ubuntu jammy *
Exempi Ubuntu upstream *

Potential Mitigations

References