PT-2017-14781 · Gnu+2 · Gnu Libextractor+2
Leon Zhao
·
Publicado
2017-12-06
·
Atualizado
2020-11-23
·
CVE-2017-17440
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Libextractor version 1.6
Description
The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted file of specific formats, including GIF, IT, NSFE, S3M, SID, or XM. This is demonstrated by the
EXTRACTOR xm extract method function in plugins/xm extractor.c.Recommendations
For GNU Libextractor version 1.6, consider avoiding the use of the
EXTRACTOR xm extract method function in plugins/xm extractor.c until a patch is available. Restrict access to file formats that can trigger the issue, such as GIF, IT, NSFE, S3M, SID, or XM files, to minimize the risk of exploitation.Exploit
Correção
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Gnu Libextractor
Ubuntu