MGASA-2018-0043
Dashboard / Vulnerabilities / MGASA-2018-0043
Summary: Updated libextractor packages fix security vulnerability
Details: GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c (CVE-2017-17440).
References: https://advisories.mageia.org/MGASA-2018-0043.html, https://bugs.mageia.org/show_bug.cgi?id=22240, https://lists.fedoraproject.org/archives/list/[email protected]/thread/M3U4WCFHXI3CPXBAGROGSUWCMG2M4FFG/
Affected packages
Package
Name: libextractor
Purl: pkg:rpm/mageia/libextractor?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
