In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c. A local attacker could use this for a denial of service attack.
References: http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00008.html