UBUNTU-CVE-2017-17440
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-17440
UBUNTU-CVE-2017-17440
Summary:
Details: GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
References: https://ubuntu.com/security/CVE-2017-17440, https://bugs.debian.org/883528#35, https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00000.html, https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00001.html, https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00002.html, https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00004.html, https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00005.html, https://ubuntu.com/security/notices/USN-4641-1, https://www.cve.org/CVERecord?id=CVE-2017-17440
Affected packages
Package
Name: libextractor
Purl: pkg:deb/ubuntu/libextractor@1:1.3-1ubuntu0.1~esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
