PT-2018-1954 · Gnu+2 · Gnu Libextractor+2

Published

2018-07-20

·

Updated

2020-11-23

·

CVE-2018-16430

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNU Libextractor versions prior to 1.8
Description The issue is related to an out-of-bounds read in the EXTRACTOR zip extract method() function, located in zip extractor.c. This could potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For GNU Libextractor versions prior to 1.8, consider updating to a version that includes a fix for the out-of-bounds read vulnerability in the EXTRACTOR zip extract method() function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2714
BDU:2018-01561
CVE-2018-16430
DLA-1501-1
DSA-4290-1
USN-4641-1

Affected Products

Alt Linux
Gnu Libextractor
Ubuntu