Medium severity6.5NVD Advisory· Published Dec 6, 2017· Updated May 13, 2026
CVE-2017-17440
CVE-2017-17440
Description
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
Affected products
1- cpe:2.3:a:gnu:libextractor:1.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- gnunet.org/git/libextractor.git/commit/nvdPatchThird Party Advisory
- bugs.debian.org/883528nvdExploitThird Party Advisory
- lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00000.htmlnvdExploitThird Party Advisory
- lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00001.htmlnvdExploitThird Party Advisory
- lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00002.htmlnvdExploitThird Party Advisory
- lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00004.htmlnvdExploitThird Party Advisory
- www.securityfocus.com/bid/102116nvdThird Party AdvisoryVDB Entry
- lists.gnu.org/archive/html/bug-libextractor/2017-11/msg00005.htmlnvdIssue Tracking
News mentions
0No linked articles in our index yet.