Related Vulnerabilities: CVE-2017-15922  

In GNU Libextractor before 1.6, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

Severity Low

Remote No

Type Denial of service

Description

In GNU Libextractor before 1.6, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

AVG-471 libextractor 1.5-1 1.6-1 Low Fixed

08 Nov 2017 ASA-201711-16 AVG-471 libextractor Low denial of service

http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00008.html

Tested with the reproducer against 1.5, it still causes the crash (the reporter tested with 1.4, but not 1.5).