MGASA-2017-0413
Dashboard / Vulnerabilities / MGASA-2017-0413
MGASA-2017-0413
Summary: Updated libextractor packages fix security vulnerabilities
Details: In 'EXTRACTOR_wav_extract_method' function of wav_extractor.c, the program does not check the value of sample_rate, with a crafted file, the sample_rate can be set to zero, resulting in a divide by zero and a crash (CVE-2017-15266). NULL Pointer Dereference vulnerability in libextract when getting flac meta from libFlac (CVE-2017-15267). NULL Pointer Dereference vulnerability in libextractor EXTRACTOR_nsf_extract_method() (rhbz#1501695).
References: https://advisories.mageia.org/MGASA-2017-0413.html, https://bugs.mageia.org/show_bug.cgi?id=21856, http://openwall.com/lists/oss-security/2017/10/12/15, https://lists.fedoraproject.org/archives/list/[email protected]/thread/Z3JVQF4TREMGJ5RI6JHPIZ6STU3H572K/
Affected packages
Package
Name: libextractor
Purl: pkg:rpm/mageia/libextractor?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
