CVE-2017-15922 log

Source
Severity Low
Remote No
Type Denial of service
Description
In GNU Libextractor before 1.6, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
Group Package Affected Fixed Severity Status Ticket
AVG-471 libextractor 1.5-1 1.6-1 Low Fixed
Date Advisory Group Package Severity Type
08 Nov 2017 ASA-201711-16 AVG-471 libextractor Low denial of service
References
http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00008.html
Notes
Tested with the reproducer against 1.5, it still causes the crash (the reporter tested with 1.4, but not 1.5).