Debian Security Advisory
DSA-4361-1 libextractor -- security update
- Date Reported:
- 28 Dec 2018
- Affected Packages:
- libextractor
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-20430, CVE-2018-20431.
- More information:
-
Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or memory disclosure if a malformed OLE file is processed.
For the stable distribution (stretch), these problems have been fixed in version 1:1.3-4+deb9u3.
We recommend that you upgrade your libextractor packages.
For the detailed security status of libextractor please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libextractor