6.8
CVSSv2

CVE-2018-14346

Published: 17/07/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

GNU Libextractor prior to 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 9.0

gnu libextractor

Vendor Advisories

Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or the execution of arbitrary code if a specially crafted file is opened For the stable distribution (stretch), these problems have been fixed in version 1:13-4+deb9u2 We recommend that you upgrade you ...
Debian Bug report logs - #907987 libextractor: CVE-2018-16430: Out of Bound Read Package: src:libextractor; Maintainer for src:libextractor is Bertrand Marc <bmarc@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 4 Sep 2018 20:27:02 UTC Severity: serious Tags: patch, security, upstream ...
Debian Bug report logs - #904903 libextractor: CVE-2018-14346: stack-buffer-underflow Package: src:libextractor; Maintainer for src:libextractor is Bertrand Marc <bmarc@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 29 Jul 2018 11:03:02 UTC Severity: serious Tags: patch, security, upstr ...
Debian Bug report logs - #904905 libextractor: CVE-2018-14347: Infinite loop in extract Package: src:libextractor; Maintainer for src:libextractor is Bertrand Marc <bmarc@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 29 Jul 2018 11:09:01 UTC Severity: serious Tags: patch, security, ups ...