ELA-972-1 exempi security update

buffer overflows

2023-09-30
Packageexempi
Version2.4.1-1+deb9u2 (stretch)
Related CVEs CVE-2020-18651 CVE-2020-18652


Buffer overflows were fixed in the functions ID3_Support::ID3v2Frame::getFrameValue() and WEBP_Support::VP8XChunk::VP8XChunk() of Exempi, an implementation of XMP (Extensible Metadata Platform).



For Debian 9 stretch, these problems have been fixed in version 2.4.1-1+deb9u2.

We recommend that you upgrade your exempi packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.