Gnu

Libextractor

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.14%
  • Veröffentlicht 25.09.2026 19:38:28
  • Zuletzt bearbeitet 30.09.2026 17:31:44

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory contai...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 15.09.2026 00:35:43
  • Zuletzt bearbeitet 24.09.2026 21:04:40

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documen...

  • EPSS 1.7%
  • Veröffentlicht 23.08.2019 17:15:14
  • Zuletzt bearbeitet 21.11.2024 04:28:56

GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

Exploit
  • EPSS 2.24%
  • Veröffentlicht 24.12.2018 05:29:01
  • Zuletzt bearbeitet 21.11.2024 04:01:27

GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.

Exploit
  • EPSS 2.24%
  • Veröffentlicht 24.12.2018 05:29:01
  • Zuletzt bearbeitet 21.11.2024 04:01:28

GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

Exploit
  • EPSS 2.65%
  • Veröffentlicht 04.09.2018 00:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:44

GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.

Exploit
  • EPSS 2.09%
  • Veröffentlicht 17.07.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:48:52

GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

Exploit
  • EPSS 1.72%
  • Veröffentlicht 17.07.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:48:52

GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).

Exploit
  • EPSS 2.36%
  • Veröffentlicht 06.12.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by th...

Exploit
  • EPSS 1.31%
  • Veröffentlicht 26.10.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.