CVE-2017-15602Infinite Loop in Libextractor

CWE-835Infinite Loop7 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 38.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 18
Latest updateMay 13

Description

In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debiangnu/libextractor< 1:1.6-1+3

🔴Vulnerability Details

3
GHSA
GHSA-ghp6-q6jg-fc8q: In GNU Libextractor 12022-05-13
OSV
CVE-2017-15602: In GNU Libextractor 12017-10-18
CVEList
CVE-2017-15602: In GNU Libextractor 12017-10-18

📋Vendor Advisories

2
Ubuntu
libextractor vulnerabilities2020-11-23
Debian
CVE-2017-15602: libextractor - In GNU Libextractor 1.4, there is an integer signedness error for the chunk size...2017

💬Community

1
Bugzilla
CVE-2017-15602 libextractor: Integer signedness error in the EXTRACTOR_nsfe_extract_method function2017-11-08
CVE-2017-15602 — Infinite Loop in GNU Libextractor | cvebase