PT-2018-2637 · Gnu+2 · Gnu Libextractor+2

Published

2018-12-24

·

Updated

2020-11-23

·

CVE-2018-20430

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Libextractor versions prior to 1.9
Description The issue is related to an out-of-bounds read in the history extract() function in plugins/ole2 extractor.c, which is connected to EXTRACTOR common convert to utf8 in common/convert.c. Additionally, the process metadata function in ole2 extractor.c is also associated with this out-of-bounds read problem. This could potentially allow a remote attacker to cause a denial of service or disclose protected information.
Recommendations For GNU Libextractor versions prior to 1.9, consider updating to a version that includes a fix for this issue, as no specific workaround is provided for these versions. As a temporary workaround, consider disabling the history extract() function in plugins/ole2 extractor.c until a patch is available. Restrict access to the ole2 extractor.c module to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1218
BDU:2019-01254
CVE-2018-20430
DLA-1616-1
DSA-4361-1
MGASA-2019-0013
USN-4641-1

Affected Products

Alt Linux
Gnu Libextractor
Ubuntu