First published: Wed Oct 18 2017(Updated: )
In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libextractor | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15602 has a medium severity rating due to the potential for an infinite loop condition.
To fix CVE-2017-15602, update GNU Libextractor to version 1.6 or later.
CVE-2017-15602 specifically affects GNU Libextractor version 1.4.
CVE-2017-15602 is associated with an integer signedness error.
CVE-2017-15602 can potentially be exploited via crafted input, leading to an infinite loop.