CVE-2006-2458
libextractor - buffer overflow
EPSS 8.9%
描述
Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).
如何修補 CVE-2006-2458
要修補 CVE-2006-2458,請將受影響套件升級到下列已修補版本。
- Debian/libextractor—升級至 0.5.14-1 或更新版本
- Debian/libextractor—升級至 0.4.2-2sarge5 或更新版本
- PyPI/extractor—未列出修補版本
- —未列出修補版本
CVE-2006-2458 正在被利用嗎?
中等 — EPSS 為 8.9%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 0.5.14-1
- from 0, < 0.4.2-2sarge5