OESA-2025-2229

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-2229
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-2229.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-2229
Upstream
Published
2025-09-05T11:09:18Z
Modified
2026-08-18T01:18:11.214039625Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
exempi security update
Details

Exempi is an implementation of XMP. Version 2.x is based on Adobe XMP SDK and released under a BSD-style license like Adobe's.

Security Fix(es):

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.(CVE-2025-30305)

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.(CVE-2025-30306)

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.(CVE-2025-30307)

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.(CVE-2025-30308)

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.(CVE-2025-30309)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / exempi

Package

Name
exempi
Purl
pkg:rpm/openEuler/exempi&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.2-5.oe2203sp4

Ecosystem specific

{
    "x86_64": [
        "exempi-2.5.2-5.oe2203sp4.x86_64.rpm",
        "exempi-debuginfo-2.5.2-5.oe2203sp4.x86_64.rpm",
        "exempi-debugsource-2.5.2-5.oe2203sp4.x86_64.rpm",
        "exempi-devel-2.5.2-5.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "exempi-2.5.2-5.oe2203sp4.aarch64.rpm",
        "exempi-debuginfo-2.5.2-5.oe2203sp4.aarch64.rpm",
        "exempi-debugsource-2.5.2-5.oe2203sp4.aarch64.rpm",
        "exempi-devel-2.5.2-5.oe2203sp4.aarch64.rpm"
    ],
    "src": [
        "exempi-2.5.2-5.oe2203sp4.src.rpm"
    ],
    "noarch": [
        "exempi-help-2.5.2-5.oe2203sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2025-2229.json"