Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:3066 - Security Advisory
Issued:
2024-05-22
Updated:
2024-05-22

RHSA-2024:3066 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: exempi security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for exempi is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Exempi provides a library for easy parsing of XMP metadata.

Security Fix(es):

  • exempi: denial of service via opening of crafted audio file with ID3V2 frame (CVE-2020-18651)
  • exempi: denial of service via opening of crafted webp file (CVE-2020-18652)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.10 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x

Fixes

  • BZ - 2235669 - CVE-2020-18651 exempi: denial of service via opening of crafted audio file with ID3V2 frame
  • BZ - 2235673 - CVE-2020-18652 exempi: denial of service via opening of crafted webp file

CVEs

  • CVE-2020-18651
  • CVE-2020-18652

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.10_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
exempi-2.4.5-4.el8.src.rpm SHA-256: 65ccadd2c5b18f21882abb3167e87814e3afa98252aec0e6574fecc6d82a9f95
x86_64
exempi-2.4.5-4.el8.i686.rpm SHA-256: 4c13fc443954b2e8e7564431a320a57a8900134cffde6124be11d09565a893c7
exempi-2.4.5-4.el8.x86_64.rpm SHA-256: 9cf59b77b8c09df204d0c6c9bcb89ec10be458f203acb9597fb70ab263b101b2
exempi-debuginfo-2.4.5-4.el8.i686.rpm SHA-256: dcb698cf61bf64572a9ac9aa2a455e10dcc3e89791541215ab15beb00fb26b2e
exempi-debuginfo-2.4.5-4.el8.x86_64.rpm SHA-256: fcc15f98da562c4234627481ac8e2ecc3f43bf94d06f89d2180bfe1e46dd044e
exempi-debugsource-2.4.5-4.el8.i686.rpm SHA-256: 5ac98d8a285f0749cad1ab7128eee928d3451b763a42faf180451994316c49ac
exempi-debugsource-2.4.5-4.el8.x86_64.rpm SHA-256: 1182b6160fb308328ab78e253adb94350beadc31197d1115da727c675e685495

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
exempi-2.4.5-4.el8.src.rpm SHA-256: 65ccadd2c5b18f21882abb3167e87814e3afa98252aec0e6574fecc6d82a9f95
s390x
exempi-2.4.5-4.el8.s390x.rpm SHA-256: 305684194c6f5ac1aa43be19f6ae0223a90a79d40b31906aafcd4319af8dbc1f
exempi-debuginfo-2.4.5-4.el8.s390x.rpm SHA-256: 12c0f2a9538b3515e175962b23baa7b1cdc5abd2c02cc76463e0f4680c1ed80e
exempi-debugsource-2.4.5-4.el8.s390x.rpm SHA-256: 431daed73c877676ce44bb8c7393ce16be644db9b3ca352cd0b45626866ddf5b

Red Hat Enterprise Linux for Power, little endian 8

SRPM
exempi-2.4.5-4.el8.src.rpm SHA-256: 65ccadd2c5b18f21882abb3167e87814e3afa98252aec0e6574fecc6d82a9f95
ppc64le
exempi-2.4.5-4.el8.ppc64le.rpm SHA-256: f65ce15a63f4042314cce879f649ba4bfe28d7070664c9612b6a7f707015b959
exempi-debuginfo-2.4.5-4.el8.ppc64le.rpm SHA-256: 45a9b39f9c6e3be219c6efb20db91eab8a9dbfcfcbefe483e4d41cc6a4766cef
exempi-debugsource-2.4.5-4.el8.ppc64le.rpm SHA-256: 47e387319839be2c41c922b7b7ed7ccdb6bd75c3676b9fed4da59efa94cdb89c

Red Hat Enterprise Linux for ARM 64 8

SRPM
exempi-2.4.5-4.el8.src.rpm SHA-256: 65ccadd2c5b18f21882abb3167e87814e3afa98252aec0e6574fecc6d82a9f95
aarch64
exempi-2.4.5-4.el8.aarch64.rpm SHA-256: 074fbecb6669b2eff8d8c04f94c57db1476895b6225aee1fdc8368a0bc9ca263
exempi-debuginfo-2.4.5-4.el8.aarch64.rpm SHA-256: 6d3bedafdc514d38c39008364b9b12c45c04145bc9140defd2cfb02f67be6b30
exempi-debugsource-2.4.5-4.el8.aarch64.rpm SHA-256: 0f0a0942372d121cfcbf2873afab76303b5a53da52ce60097049cd9f175b5609

Red Hat CodeReady Linux Builder for x86_64 8

SRPM
x86_64
exempi-debuginfo-2.4.5-4.el8.i686.rpm SHA-256: dcb698cf61bf64572a9ac9aa2a455e10dcc3e89791541215ab15beb00fb26b2e
exempi-debuginfo-2.4.5-4.el8.x86_64.rpm SHA-256: fcc15f98da562c4234627481ac8e2ecc3f43bf94d06f89d2180bfe1e46dd044e
exempi-debugsource-2.4.5-4.el8.i686.rpm SHA-256: 5ac98d8a285f0749cad1ab7128eee928d3451b763a42faf180451994316c49ac
exempi-debugsource-2.4.5-4.el8.x86_64.rpm SHA-256: 1182b6160fb308328ab78e253adb94350beadc31197d1115da727c675e685495
exempi-devel-2.4.5-4.el8.i686.rpm SHA-256: a1109433be6c19c0f9723fa0d48207174ee5d6a0ff08613c5e0138f23e682232
exempi-devel-2.4.5-4.el8.x86_64.rpm SHA-256: 5ed257ad127b9cde51f13926cfd53b9db4f907836161d1fad9f1b4beac275a10

Red Hat CodeReady Linux Builder for Power, little endian 8

SRPM
ppc64le
exempi-debuginfo-2.4.5-4.el8.ppc64le.rpm SHA-256: 45a9b39f9c6e3be219c6efb20db91eab8a9dbfcfcbefe483e4d41cc6a4766cef
exempi-debugsource-2.4.5-4.el8.ppc64le.rpm SHA-256: 47e387319839be2c41c922b7b7ed7ccdb6bd75c3676b9fed4da59efa94cdb89c
exempi-devel-2.4.5-4.el8.ppc64le.rpm SHA-256: 8a950794fc1e0924a50f6a7a9d5135619b7ce8329380743b8d7b540ae24df19a

Red Hat CodeReady Linux Builder for ARM 64 8

SRPM
aarch64
exempi-debuginfo-2.4.5-4.el8.aarch64.rpm SHA-256: 6d3bedafdc514d38c39008364b9b12c45c04145bc9140defd2cfb02f67be6b30
exempi-debugsource-2.4.5-4.el8.aarch64.rpm SHA-256: 0f0a0942372d121cfcbf2873afab76303b5a53da52ce60097049cd9f175b5609
exempi-devel-2.4.5-4.el8.aarch64.rpm SHA-256: 3c35d332caa77392672b3de1840afb6acac98e69c2c3edda280f742b492b7248

Red Hat CodeReady Linux Builder for IBM z Systems 8

SRPM
s390x
exempi-debuginfo-2.4.5-4.el8.s390x.rpm SHA-256: 12c0f2a9538b3515e175962b23baa7b1cdc5abd2c02cc76463e0f4680c1ed80e
exempi-debugsource-2.4.5-4.el8.s390x.rpm SHA-256: 431daed73c877676ce44bb8c7393ce16be644db9b3ca352cd0b45626866ddf5b
exempi-devel-2.4.5-4.el8.s390x.rpm SHA-256: 19846098ee6be03b06b55cc0203faa012ba2598e6ef737dc51864908c6d2a547

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility