PT-2006-7563 · Gnu · Libextractor

Luigi Auriemma

·

Published

1970-01-01

·

Updated

2022-05-01

·

CVE-2006-2458

CVSS v2.0

4.0

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions libextractor versions prior to 0.5.14
Description The issue concerns multiple heap-based buffer overflows in libextractor, which can be exploited remotely to execute arbitrary code. This can lead to a breach of confidentiality and integrity of protected information. The exploitation can be carried out via functions such as the asf read header function in the ASF plugin and the parse trak atom function in the QT plugin.
Recommendations For versions prior to 0.5.14, update to version 0.5.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable plugins, such as the ASF and QT plugins, until a patch is available. Avoid using the asf read header and parse trak atom functions in the affected plugins until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03482
BDU:2015-03483
BDU:2015-03484
BDU:2015-09512
CVE-2006-2458
DSA-1081-1
GHSA-F836-7JQW-3684
PYSEC-2006-4

Affected Products

Libextractor