Infinite loop in Libextractor - CVE-2018-14347
Published: October 14, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in EXTRACTOR_mpeg_extract_method function in mpeg_extractor.c. A remote attacker use a specially crafted archive file to consume all available system resources and cause denial of service conditions.
Affected software
libextractor (Debian package)
extract (Ubuntu package)
libextractor-dev (Ubuntu package)
libextractor3 (Ubuntu package)
Ubuntu
How to mitigate CVE-2018-14347
libextractor (Debian package) - update to 1:1.3-4+deb9u2
extract (Ubuntu package) - update to 1:1.3-4+deb9u3build0.16.04.1
libextractor-dev (Ubuntu package) - update to 1:1.3-4+deb9u3build0.16.04.1
libextractor3 (Ubuntu package) - update to 1:1.3-4+deb9u3build0.16.04.1
External References
- http://lists.gnu.org/archive/html/bug-libextractor/2018-07/msg00000.html
- https://gnunet.org/bugs/view.php?id=5399
- https://gnunet.org/git/libextractor.git/commit/?id=f033468cd36e2b8bf92d747fbd683b2ace8da394
- https://lists.debian.org/debian-lts-announce/2018/08/msg00025.html
- https://www.debian.org/security/2018/dsa-4290