Medium severity6.5NVD Advisory· Published Dec 24, 2018· Updated Jun 17, 2026
CVE-2018-20431
CVE-2018-20431
Description
GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5<=1.8+ 2 more
- (no CPE)range: <=1.8
- (no CPE)range: <=1.8
- cpe:2.3:a:gnu:libextractor:*:*:*:*:*:*:*:*range: <=1.8
Patches
Vulnerability mechanics
References
6- gnunet.org/git/libextractor.git/commit/nvdPatchThird Party Advisory
- gnunet.org/bugs/view.phpnvdExploitIssue TrackingThird Party Advisory
- www.securityfocus.com/bid/106300nvdThird Party AdvisoryVDB Entry
- gnunet.org/git/libextractor.git/tree/ChangeLognvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/12/msg00015.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2018/dsa-4361nvdThird Party Advisory
News mentions
0No linked articles in our index yet.