Null pointer dereference in Libextractor - CVE-2017-17440
Published: July 26, 2018 / Updated: July 26, 2018
Libextractor
Detailed vulnerability description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c due to an error when processing malicious input. A remote attacker can send a specially crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, trigger NULL pointer derference and cause the service to crash.