CVE-2017-15602: High severity GNU Libextractor vulnerability
Published Oct 18, 2017
·Updated
In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTORnsfeextractmethod function in plugins/nsfeextractor.c, leading to an infinite loop for a crafted size.
Affected Software
1 affected component
GNU Libextractor=1.4
Event History
Oct 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15602?
CVE-2017-15602 has a medium severity rating due to the potential for an infinite loop condition.
2
How do I fix CVE-2017-15602?
To fix CVE-2017-15602, update GNU Libextractor to version 1.6 or later.
3
What software does CVE-2017-15602 affect?
CVE-2017-15602 specifically affects GNU Libextractor version 1.4.
4
What type of error is associated with CVE-2017-15602?
CVE-2017-15602 is associated with an integer signedness error.
5
Can CVE-2017-15602 be exploited remotely?
CVE-2017-15602 can potentially be exploited via crafted input, leading to an infinite loop.