An exempi security update has been released for Debian GNU/Linux 9 LTS to address buffer overflows.
ELA-972-1 exempi security update
Package : exempi
Version : 2.4.1-1+deb9u2 (stretch)
Related CVEs :
CVE-2020-18651
CVE-2020-18652
Buffer overflows were fixed in the functions ID3_Support::ID3v2Frame::getFrameValue()
and WEBP_Support::VP8XChunk::VP8XChunk() of Exempi, an implementation of XMP (Extensible Metadata Platform).