Publishing details

Changelog

libextractor (1:1.3-4+deb9u3build0.16.04.1) xenial-security; urgency=medium

  * fake sync from Debian

libextractor (1:1.3-4+deb9u3) stretch-security; urgency=high

  * Fix out-of-bounds read vulnerability in common/convert.c (Closes: #917214,
    CVE-2018-20430).
  * Fix NULL pointer dereference in OLE2 extractor (Closes: #917213,
    CVE-2018-20431).

libextractor (1:1.3-4+deb9u2) stretch-security; urgency=high

  * Fix CVE-2018-14346 (Closes: #904903), a stack-based buffer overflow
    in unzip.c.
  * Fix CVE-2018-14347 (Closes: #904905), infinite loop vulnerability in
    mpeg_extractor.c.
  * Fix CVE-2018-16430 (Closes: #907987), missing 0-terminator on corrupted
    ZIP files.

libextractor (1:1.3-4+deb9u1) stretch; urgency=medium

  * Fix CVE-2017-15266, CVE-2017-15267, CVE-2017-15600, CVE-2017-15601,
    CVE-2017-15602, CVE-2017-15922 and CVE-2017-17440. Leon Zhao discovered
    several security vulnerabilities, NULL Pointer Dereferences, heap-based
    buffer overflows, integer signedness errors and out-of-bounds read that
    may lead to a denial-of-service (application crash) or have other
    unspecified impact.

libextractor (1:1.3-4) unstable; urgency=medium

  * Update debian/patches/ffmpeg2.9.patch with a new commit taken from upstream
    svn, to make libextractor build with FFmpeg 2.9 (Closes: #803835).
  * Standards-version: 3.9.8.
  * debian/control: use secure URI for the Vcs-* fields.

 -- Mike Salvatore <email address hidden>  Mon, 23 Nov 2020 11:03:49 -0500

Available diffs

Builds

Built packages

Package files