GNU Libextractor is prone to multiple security vulnerabilities. https://gnunet.org/bugs/view.php?id=5494 https://gnunet.org/bugs/view.php?id=5493 1. A remote denial-of-service vulnerability 2. An out-of-bound read access vulnerability Attackers can exploit these issues to crash the application denying service to legitimate users or disclose sensitive information that may aid in further attacks.
Apparently fixed in upstream 1.9.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=10ca5198d87e67194880e4421dc4a3d348211008 commit 10ca5198d87e67194880e4421dc4a3d348211008 Author: Andreas Sturmlechner <asturm@gentoo.org> AuthorDate: 2018-12-29 20:21:07 +0000 Commit: Andreas Sturmlechner <asturm@gentoo.org> CommitDate: 2018-12-29 22:02:01 +0000 media-libs/libextractor: Fix CVE-2018-20430, CVE-2018-20431 Bug: https://bugs.gentoo.org/673742 Package-Manager: Portage-2.3.52, Repoman-2.3.12 Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> .../files/libextractor-1.8-CVE-2018-20430.patch | 49 +++++++++ .../files/libextractor-1.8-CVE-2018-20431.patch | 39 +++++++ media-libs/libextractor/libextractor-1.8-r1.ebuild | 117 +++++++++++++++++++++ 3 files changed, 205 insertions(+)
Arches, please stabilise.
Looking good on ppc/ppc64. # cat /mnt/mychroot/root/tatt/libextractor-673742.report USE tests started on So 30. Dez 15:32:37 CET 2018 FEATURES=' test' USE='' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 -ffmpeg -flac gif -gsf -gstreamer -gtk jpeg -magic midi mp4 mpeg -tidy tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive bzip2 ffmpeg -flac -gif -gsf -gstreamer gtk jpeg -magic -midi mp4 -mpeg -tidy tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive -bzip2 -ffmpeg -flac -gif -gsf -gstreamer gtk jpeg -magic -midi -mp4 mpeg -tidy tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive -bzip2 -ffmpeg -flac -gif -gsf gstreamer -gtk jpeg -magic -midi mp4 -mpeg tidy tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive -bzip2 ffmpeg flac -gif -gsf gstreamer gtk -jpeg -magic -midi mp4 -mpeg -tidy -tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg flac gif -gsf -gstreamer -gtk -jpeg -magic midi -mp4 mpeg tidy -tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg flac -gif gsf gstreamer gtk jpeg magic midi mp4 mpeg tidy -tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg -flac gif -gsf -gstreamer gtk -jpeg magic midi mp4 -mpeg tidy -tiff vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 -ffmpeg -flac gif gsf -gstreamer gtk -jpeg magic midi mp4 -mpeg tidy -tiff vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 -ffmpeg -flac -gif gsf gstreamer -gtk jpeg -magic midi -mp4 mpeg -tidy tiff vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive -bzip2 -ffmpeg flac -gif -gsf -gstreamer -gtk jpeg -magic -midi mp4 mpeg -tidy tiff vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive -bzip2 ffmpeg flac gif -gsf gstreamer -gtk jpeg -magic midi mp4 mpeg tidy tiff vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 revdep tests started on So 30. Dez 16:30:41 CET 2018 FEATURES=' test' USE='' succeeded for dev-python/libextractor-python # cat libextractor-673742.report USE tests started on So 30. Dez 20:56:08 CET 2018 FEATURES=' test' USE='' succeeded for =media-libs/libextractor-1.8-r1 USE='archive -bzip2 ffmpeg flac -gif gsf gstreamer gtk -jpeg -magic -midi -mp4 mpeg -tidy -tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg flac gif gsf gstreamer -gtk -jpeg -magic -midi mp4 -mpeg tidy -tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg -flac -gif gsf -gstreamer -gtk -jpeg -magic -midi -mp4 mpeg -tidy tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive -bzip2 -ffmpeg flac -gif gsf -gstreamer -gtk -jpeg -magic midi -mp4 mpeg -tidy tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg -flac gif gsf -gstreamer -gtk -jpeg -magic midi mp4 mpeg -tidy tiff -vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg -flac -gif gsf -gstreamer -gtk -jpeg magic midi -mp4 -mpeg -tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive bzip2 ffmpeg -flac -gif -gsf gstreamer gtk jpeg -magic midi mp4 mpeg tidy -tiff vorbis -zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive -bzip2 ffmpeg -flac -gif -gsf -gstreamer gtk jpeg magic -midi mp4 -mpeg tidy -tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg flac gif -gsf gstreamer -gtk jpeg magic midi mp4 mpeg -tidy tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive -bzip2 ffmpeg -flac gif -gsf gstreamer gtk -jpeg magic -midi -mp4 -mpeg tidy tiff -vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='-archive -bzip2 ffmpeg flac gif gsf -gstreamer gtk jpeg magic -midi mp4 mpeg -tidy -tiff vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 USE='archive bzip2 ffmpeg flac -gif -gsf -gstreamer gtk -jpeg -magic midi -mp4 -mpeg -tidy tiff vorbis zlib' succeeded for =media-libs/libextractor-1.8-r1 revdep tests started on So 30. Dez 21:15:47 CET 2018 FEATURES=' test' USE='' succeeded for dev-python/libextractor-python
ppc stable
ppc64 stable
x86 stable
amd64 stable