First published: Mon Dec 24 2018(Updated: )
GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libextractor | 1:1.8-2+deb10u1 1:1.11-2 1:1.11-7 1:1.11-8 | |
libextractor | <=1.8 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-20430 is moderate due to the potential for an out-of-bounds read vulnerability.
To fix CVE-2018-20430, update GNU Libextractor to versions 1:1.8-2+deb10u1, 1:1.11-2, 1:1.11-7, or 1:1.11-8.
GNU Libextractor versions up to and including 1.8 are affected by CVE-2018-20430.
CVE-2018-20430 affects GNU Libextractor running on Debian GNU/Linux versions 8.0 and 9.0.
The vulnerability in CVE-2018-20430 is related to the function history_extract() in plugins/ole2_extractor.c.