Bug 1524552 (CVE-2017-17440) - CVE-2017-17440 libextractor: NULL pointer dereference in the EXTRACTOR_xm_extract_method function
Summary: CVE-2017-17440 libextractor: NULL pointer dereference in the EXTRACTOR_xm_ext...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2017-17440
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1524553
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-12-11 16:41 UTC by Andrej Nemec
Modified: 2019-09-29 14:28 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-08 03:33:27 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2017-12-11 16:41:29 UTC
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.

References:

https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00000.html

Upstream patch:

https://gnunet.org/git/libextractor.git/commit/?id=7cc63b001ceaf81143795321379c835486d0c92e

Comment 1 Andrej Nemec 2017-12-11 16:42:43 UTC
Created libextractor tracking bugs for this issue:

Affects: fedora-all [bug 1524553]


Note You need to log in before you can comment on or make changes to this bug.