cbcvebase.

Debian Libextractor vulnerabilities

29 known vulnerabilities affecting debian/libextractor.

Total CVEs
29
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH6MEDIUM10LOW10

Vulnerabilities

Page 2 of 2
CVE-2018-14347P4MEDIUMCVSS 6.5fixed in libextractor 1:1.7-1 (bookworm)2018
CVE-2018-14347 [MEDIUM] CVE-2018-14347: libextractor - GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR... GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c). Scope: local bookworm: resolved (fixed in 1:1.7-1) bullseye: resolved (fixed in 1:1.7-1) forky: resolved (fixed in 1:1.7-1) sid: resolved (fixed in 1:1.7-1) trixie: resolved (fixed in 1:1.7-1)
debian
CVE-2019-15531P4MEDIUMCVSS 6.5fixed in libextractor 1:1.9-2 (bookworm)2019
CVE-2019-15531 [MEDIUM] CVE-2019-15531: libextractor - GNU Libextractor through 1.9 has a heap-based buffer over-read in the function E... GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c. Scope: local bookworm: resolved (fixed in 1:1.9-2) bullseye: resolved (fixed in 1:1.9-2) forky: resolved (fixed in 1:1.9-2) sid: resolved (fixed in 1:1.9-2) trixie: resolved (fixed in 1:1.9-2)
debian
CVE-2017-17440P4MEDIUMCVSS 6.5fixed in libextractor 1:1.6-2 (bookworm)2017
CVE-2017-17440 [MEDIUM] CVE-2017-17440: libextractor - GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL ... GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c. Scope: local bookworm: resolved (fixed in 1:1
debian
CVE-2009-3736P4LOWCVSS 6.9fixed in clamav 0.95+dfsg-1 (bookworm)2009
CVE-2009-3736 [MEDIUM] CVE-2009-3736: bochs - ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham ... ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2017-15266P4MEDIUMCVSS 5.5fixed in libextractor 1:1.6-1 (bookworm)2017
CVE-2017-15266 [MEDIUM] CVE-2017-15266: libextractor - In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_meth... In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate. Scope: local bookworm: resolved (fixed in 1:1.6-1) bullseye: resolved (fixed in 1:1.6-1) forky: resolved (fixed in 1:1.6-1) sid: resolved (fixed in 1:1.6-1) trixie: resolved (fixed in 1:1.6-1)
debian
CVE-2005-3624P4MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3624 [MEDIUM] CVE-2005-3624: cups - The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, p... The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1
debian
CVE-2005-3626P4MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3626 [MEDIUM] CVE-2005-3626: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l... Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) sid: resolved (fix
debian
CVE-2017-15922P4LOWCVSS 5.5fixed in libextractor 1:1.6-2 (bookworm)2017
CVE-2017-15922 [MEDIUM] CVE-2017-15922: libextractor - In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_ext... In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c. Scope: local bookworm: resolved (fixed in 1:1.6-2) bullseye: resolved (fixed in 1:1.6-2) forky: resolved (fixed in 1:1.6-2) sid: resolved (fixed in 1:1.6-2) trixie: resolved (fixed in 1:1.6-2)
debian
CVE-2005-2097P4LOWCVSS 2.1fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-2097 [LOW] CVE-2005-2097: cups - xpdf and kpdf do not properly validate the "loca" table in PDF files, which allo... xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed
debian
Debian Libextractor vulnerabilities | cvebase