Vulnerability Description
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Libextractor | 1.6 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102116Third Party AdvisoryVDB Entry
- https://bugs.debian.org/883528#35ExploitThird Party Advisory
- https://gnunet.org/git/libextractor.git/commit/?id=7cc63b001ceaf81143795321379c8PatchThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00000.htmlExploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00001.htmlExploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00002.htmlExploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00004.htmlExploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00005.htmlIssue Tracking
- http://www.securityfocus.com/bid/102116Third Party AdvisoryVDB Entry
- https://bugs.debian.org/883528#35ExploitThird Party Advisory
- https://gnunet.org/git/libextractor.git/commit/?id=7cc63b001ceaf81143795321379c8PatchThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00000.htmlExploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00001.htmlExploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00002.htmlExploitThird Party Advisory
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00004.htmlExploitThird Party Advisory
FAQ
What is CVE-2017-17440?
CVE-2017-17440 is a vulnerability with a CVSS score of 6.5 (MEDIUM). GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, o...
How severe is CVE-2017-17440?
CVE-2017-17440 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17440?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Libextractor.