Debian Libextractor vulnerabilities
29 known vulnerabilities affecting debian/libextractor.
Total CVEs
29
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH6MEDIUM10LOW10
Vulnerabilities
Page 1 of 2
CVE-2006-2458P3MEDIUMCVSS 4.0PoCfixed in libextractor 0.5.14-1 (bookworm)2006
CVE-2006-2458 [MEDIUM] CVE-2006-2458: libextractor - Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow re...
Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).
Scope: local
bookworm: resolved (fixed in 0.5.14-1)
bullseye: resolved (fixed in 0
debian
CVE-2018-14346P3HIGHCVSS 8.8fixed in libextractor 1:1.7-1 (bookworm)2018
CVE-2018-14346 [HIGH] CVE-2018-14346: libextractor - GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_fu...
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
Scope: local
bookworm: resolved (fixed in 1:1.7-1)
bullseye: resolved (fixed in 1:1.7-1)
forky: resolved (fixed in 1:1.7-1)
sid: resolved (fixed in 1:1.7-1)
trixie: resolved (fixed in 1:1.7-1)
debian
CVE-2007-5392P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5392 [CRITICAL] CVE-2007-5392: cups - Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p1...
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22-7)
trixie: r
debian
CVE-2007-5393P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5393 [CRITICAL] CVE-2007-5393: cups - Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream...
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22
debian
CVE-2007-4352P3HIGHCVSS 7.6fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-4352 [HIGH] CVE-2007-4352: cups - Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Strea...
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: re
debian
CVE-2007-3387P3LOWCVSS 6.8fixed in libextractor 0.5.12-1 (bookworm)2007
CVE-2007-3387 [MEDIUM] CVE-2007-3387: cups - Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, ...
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine fu
debian
CVE-2018-16430P3HIGHCVSS 8.8fixed in libextractor 1:1.7-1 (bookworm)2018
CVE-2018-16430 [HIGH] CVE-2018-16430: libextractor - GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTO...
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
Scope: local
bookworm: resolved (fixed in 1:1.7-1)
bullseye: resolved (fixed in 1:1.7-1)
forky: resolved (fixed in 1:1.7-1)
sid: resolved (fixed in 1:1.7-1)
trixie: resolved (fixed in 1:1.7-1)
debian
CVE-2005-3192P3LOWCVSS 7.5fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3192 [HIGH] CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used...
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2017-15601P3LOWCVSS 7.5fixed in libextractor 1:1.6-1 (bookworm)2017
CVE-2017-15601 [HIGH] CVE-2017-15601: libextractor - In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_...
In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to processiTXt and stndup.
Scope: local
bookworm: resolved (fixed in 1:1.6-1)
bullseye: resolved (fixed in 1:1.6-1)
forky: resolved (fixed in 1:1.6-1)
sid: resolved (fixed in 1:1.6-1)
trixie: resolved (fixed in 1:1.6-1)
debian
CVE-2017-15267P4HIGHCVSS 7.5fixed in libextractor 1:1.6-1 (bookworm)2017
CVE-2017-15267 [HIGH] CVE-2017-15267: libextractor - In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in...
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.
Scope: local
bookworm: resolved (fixed in 1:1.6-1)
bullseye: resolved (fixed in 1:1.6-1)
forky: resolved (fixed in 1:1.6-1)
sid: resolved (fixed in 1:1.6-1)
trixie: resolved (fixed in 1:1.6-1)
debian
CVE-2005-3627P4HIGHCVSS 7.5fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3627 [HIGH] CVE-2005-3627: cups - Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, t...
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index
debian
CVE-2006-0301P4MEDIUMCVSS 7.5fixed in libextractor 0.5.10-1 (bookworm)2006
CVE-2006-0301 [HIGH] CVE-2006-0301: libextractor - Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such ...
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
Scope: local
b
debian
CVE-2017-15600P4LOWCVSS 7.5fixed in libextractor 1:1.6-1 (bookworm)2017
CVE-2017-15600 [HIGH] CVE-2017-15600: libextractor - In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_ns...
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.
Scope: local
bookworm: resolved (fixed in 1:1.6-1)
bullseye: resolved (fixed in 1:1.6-1)
forky: resolved (fixed in 1:1.6-1)
sid: resolved (fixed in 1:1.6-1)
trixie: resolved (fixed in 1:1.6-1)
debian
CVE-2017-15602P4LOWCVSS 7.5fixed in libextractor 1:1.6-1 (bookworm)2017
CVE-2017-15602 [HIGH] CVE-2017-15602: libextractor - In GNU Libextractor 1.4, there is an integer signedness error for the chunk size...
In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.
Scope: local
bookworm: resolved (fixed in 1:1.6-1)
bullseye: resolved (fixed in 1:1.6-1)
forky: resolved (fixed in 1:1.6-1)
sid: resolved (fixed in 1:1.6-1)
tr
debian
CVE-2005-3628P4HIGHCVSS 7.5fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3628 [HIGH] CVE-2005-3628: cups - Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xp...
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
f
debian
CVE-2005-3625P4CRITICALCVSS 10.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3625 [CRITICAL] CVE-2005-3625: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l...
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved
debian
CVE-2018-20430P4MEDIUMCVSS 6.5fixed in libextractor 1:1.8-2 (bookworm)2018
CVE-2018-20430 [MEDIUM] CVE-2018-20430: libextractor - GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the func...
GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
Scope: local
bookworm: resolved (fixed in 1:1.8-2)
bullseye: resolved (fixed in 1:1.8-2)
forky: resolved (fixed in 1:1.8-2)
sid: resolved (fixed in 1:1.8-2)
trixie:
debian
CVE-2005-3193P4LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3193 [MEDIUM] CVE-2005-3193: cups - Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX ...
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF f
debian
CVE-2005-3191P4LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3191 [MEDIUM] CVE-2005-3191: cups - Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF an...
Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial
debian
CVE-2018-20431P4MEDIUMCVSS 6.5fixed in libextractor 1:1.8-2 (bookworm)2018
CVE-2018-20431 [MEDIUM] CVE-2018-20431: libextractor - GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the...
GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.
Scope: local
bookworm: resolved (fixed in 1:1.8-2)
bullseye: resolved (fixed in 1:1.8-2)
forky: resolved (fixed in 1:1.8-2)
sid: resolved (fixed in 1:1.8-2)
trixie: resolved (fixed in 1:1.8-2)
debian
1 / 2Next →