USN-4641-1
Dashboard / Vulnerabilities / USN-4641-1
USN-4641-1
Summary: libextractor vulnerabilities
Details: It was discovered that Libextractor incorrectly handled zero sample rate. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-15266) It was discovered that Libextractor incorrectly handled certain FLAC metadata. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-15267) It was discovered that Libextractor incorrectly handled certain specially crafted files. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-15600, CVE-2018-16430, CVE-2018-20430) It was discovered that Libextractor incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-15601) It was discovered that Libextractor incorrectly handled integers. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-15602) It was discovered that Libextractore incorrectly handled certain crafted files. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-15922) It was discovered tha Libextractor incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-17440) It was discovered that Libextractor incorrectly handled certain malformed files. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-14346) It was discovered that Libextractor incorrectly handled malformed files. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-14347) It was discovered that Libextractor incorrectly handled metadata. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-20431)
References: https://ubuntu.com/security/notices/USN-4641-1, https://ubuntu.com/security/CVE-2017-15266, https://ubuntu.com/security/CVE-2017-15267, https://ubuntu.com/security/CVE-2017-15600, https://ubuntu.com/security/CVE-2017-15601, https://ubuntu.com/security/CVE-2017-15602, https://ubuntu.com/security/CVE-2017-15922, https://ubuntu.com/security/CVE-2017-17440, https://ubuntu.com/security/CVE-2018-14346, https://ubuntu.com/security/CVE-2018-14347, https://ubuntu.com/security/CVE-2018-16430, https://ubuntu.com/security/CVE-2018-20430, https://ubuntu.com/security/CVE-2018-20431
Affected packages
Package
Name: libextractor
Purl: pkg:deb/ubuntu/libextractor@1:1.3-4+deb9u3build0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
