CVE-2018-14346

Severity
8.8HIGH
EPSS
0.5%
top 34.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateMay 13

Description

GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDgnu/libextractor< 1.7
Debianlibextractor< 1:1.7-1+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gfcm-4735-4cv3: GNU Libextractor before 12022-05-13
CVEList
CVE-2018-14346: GNU Libextractor before 12018-07-17
OSV
CVE-2018-14346: GNU Libextractor before 12018-07-17

📋Vendor Advisories

2
Ubuntu
libextractor vulnerabilities2020-11-23
Debian
CVE-2018-14346: libextractor - GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_fu...2018

💬Community

2
Bugzilla
CVE-2018-14346 libextractor: Stack-based buffer overflow in unzip.c:ec_read_file_func() allows for denial of service [fedora-all]2018-07-25
Bugzilla
CVE-2018-14346 libextractor: Stack-based buffer overflow in unzip.c:ec_read_file_func() allows for denial of service2018-07-25
CVE-2018-14346 (HIGH CVSS 8.8) | GNU Libextractor before 1.7 has a s | cvebase.io