mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 10:41:43 +00:00
22 lines
1.1 KiB
Markdown
22 lines
1.1 KiB
Markdown
![]() |
### [CVE-2017-17440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17440)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://bugs.debian.org/883528#35
|
||
|
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00000.html
|
||
|
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00001.html
|
||
|
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00002.html
|
||
|
- https://lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00004.html
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/andir/nixos-issue-db-example
|
||
|
|