Name | CVE-2018-14347 |
Description | GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c). |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
References | DLA-1478-1, DSA-4290-1 |
Debian Bugs | 904905 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
libextractor (PTS) | stretch | 1:1.3-4+deb9u3 | fixed |
stretch (security) | 1:1.3-4+deb9u4 | fixed | |
buster | 1:1.8-2+deb10u1 | fixed | |
bullseye | 1:1.11-2 | fixed | |
bookworm, sid | 1:1.11-5 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
libextractor | source | jessie | 1:1.3-2+deb8u2 | DLA-1478-1 | ||
libextractor | source | stretch | 1:1.3-4+deb9u2 | DSA-4290-1 | ||
libextractor | source | (unstable) | 1:1.7-1 | 904905 |
http://lists.gnu.org/archive/html/bug-libextractor/2018-07/msg00000.html
https://gnunet.org/bugs/view.php?id=5399
https://git.gnunet.org/libextractor.git/commit/?id=f033468cd36e2b8bf92d747fbd683b2ace8da394