Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15602

Опубликовано: 18 окт. 2017
Источник: debian

Описание

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libextractorfixed1:1.6-1package
libextractorfixed1:1.3-4+deb9u1stretchpackage
libextractorfixed1:1.3-2+deb8u1jessiepackage

Примечания

  • http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00005.html

  • Fixed by https://git.gnunet.org/libextractor.git/commit/?id=ffab889c1710c7646af9ed360c796a2a0a619efc

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.

CVSS3: 7.5
nvd
больше 8 лет назад

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.

CVSS3: 7.5
github
больше 3 лет назад

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.