6.8
CVSSv2

CVE-2018-16430

Published: 04/09/2018 Updated: 25/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

GNU Libextractor up to and including 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu libextractor

debian debian linux 9.0

debian debian linux 8.0

Vendor Advisories

Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or the execution of arbitrary code if a specially crafted file is opened For the stable distribution (stretch), these problems have been fixed in version 1:13-4+deb9u2 We recommend that you upgrade you ...
Debian Bug report logs - #907987 libextractor: CVE-2018-16430: Out of Bound Read Package: src:libextractor; Maintainer for src:libextractor is Bertrand Marc <bmarc@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 4 Sep 2018 20:27:02 UTC Severity: serious Tags: patch, security, upstream ...
Debian Bug report logs - #904903 libextractor: CVE-2018-14346: stack-buffer-underflow Package: src:libextractor; Maintainer for src:libextractor is Bertrand Marc <bmarc@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 29 Jul 2018 11:03:02 UTC Severity: serious Tags: patch, security, upstr ...
Debian Bug report logs - #904905 libextractor: CVE-2018-14347: Infinite loop in extract Package: src:libextractor; Maintainer for src:libextractor is Bertrand Marc <bmarc@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 29 Jul 2018 11:09:01 UTC Severity: serious Tags: patch, security, ups ...