Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.844726
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-4641-1)
Summary:The remote host is missing an update for the 'libextractor' package(s) announced via the USN-4641-1 advisory.
Description:Summary:
The remote host is missing an update for the 'libextractor' package(s) announced via the USN-4641-1 advisory.

Vulnerability Insight:
It was discovered that Libextractor incorrectly handled zero sample rate.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2017-15266)

It was discovered that Libextractor incorrectly handled certain FLAC
metadata. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-15267)

It was discovered that Libextractor incorrectly handled certain specially
crafted files. An attacker could possibly use this issue to cause a denial
of service. (CVE-2017-15600, CVE-2018-16430, CVE-2018-20430)

It was discovered that Libextractor incorrectly handled certain inputs. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2017-15601)

It was discovered that Libextractor incorrectly handled integers. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2017-15602)

It was discovered that Libextractore incorrectly handled certain crafted
files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-15922)

It was discovered thanLibextractor incorrectly handled certain files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2017-17440)

It was discovered that Libextractor incorrectly handled certain malformed
files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2018-14346)

It was discovered that Libextractor incorrectly handled malformed files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-14347)

It was discovered that Libextractor incorrectly handled metadata. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20431)

Affected Software/OS:
'libextractor' package(s) on Ubuntu 16.04.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-15266
BugTraq ID: 101271
http://www.securityfocus.com/bid/101271
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00002.html
http://openwall.com/lists/oss-security/2017/10/11/1
https://bugzilla.redhat.com/show_bug.cgi?id=1499599
https://lists.debian.org/debian-lts-announce/2017/12/msg00000.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-15267
BugTraq ID: 101272
http://www.securityfocus.com/bid/101272
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00003.html
https://bugzilla.redhat.com/show_bug.cgi?id=1499600
Common Vulnerability Exposure (CVE) ID: CVE-2017-15600
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00004.html
https://bugzilla.redhat.com/show_bug.cgi?id=1501695
https://ftp.gnu.org/gnu/libextractor/libextractor-1.6.tar.gz
Common Vulnerability Exposure (CVE) ID: CVE-2017-15601
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-15602
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-15922
BugTraq ID: 101595
http://www.securityfocus.com/bid/101595
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00008.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-17440
BugTraq ID: 102116
http://www.securityfocus.com/bid/102116
https://bugs.debian.org/883528#35
https://gnunet.org/git/libextractor.git/commit/?id=7cc63b001ceaf81143795321379c835486d0c92e
https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00000.html
https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00001.html
https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00002.html
https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00004.html
https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-14346
Debian Security Information: DSA-4290 (Google Search)
https://www.debian.org/security/2018/dsa-4290
http://lists.gnu.org/archive/html/bug-libextractor/2018-07/msg00001.html
https://gnunet.org/git/libextractor.git/commit/?id=ad19e7fe0adc99d5710eff1ed48d91a7b75a950e
https://lists.debian.org/debian-lts-announce/2018/08/msg00025.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-14347
http://lists.gnu.org/archive/html/bug-libextractor/2018-07/msg00000.html
https://gnunet.org/bugs/view.php?id=5399
https://gnunet.org/git/libextractor.git/commit/?id=f033468cd36e2b8bf92d747fbd683b2ace8da394
Common Vulnerability Exposure (CVE) ID: CVE-2018-16430
BugTraq ID: 105254
http://www.securityfocus.com/bid/105254
https://gnunet.org/bugs/view.php?id=5405
https://gnunet.org/git/libextractor.git/commit/?id=24c8d489797499c0331f4d1039e357ece1ae98a7
https://lists.debian.org/debian-lts-announce/2018/09/msg00011.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-20430
BugTraq ID: 106300
http://www.securityfocus.com/bid/106300
Debian Security Information: DSA-4361 (Google Search)
https://www.debian.org/security/2018/dsa-4361
https://gnunet.org/bugs/view.php?id=5493
https://gnunet.org/git/libextractor.git/commit/?id=b405d707b36e0654900cba78e89f49779efea110
https://gnunet.org/git/libextractor.git/tree/ChangeLog
https://lists.debian.org/debian-lts-announce/2018/12/msg00015.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-20431
https://gnunet.org/bugs/view.php?id=5494
https://gnunet.org/git/libextractor.git/commit/?id=489c4a540bb2c4744471441425b8932b97a153e7
CopyrightCopyright (C) 2020 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.