RULE(RULE ID:321590)

Rule General Information
Release Date: 2018-09-18
Rule Name: MISC GNU Libextractor ZIP File Comment Out-of-Bounds Read Vulnerability(CVE-2018-16430)
Severity:
CVE ID:
Rule Protection Details
Description: GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
Impact: Attackers can exploit this issue to crash the application denying service to legitimate users or disclose sensitive information that may aid in further attacks.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android
Reference: SecurityFocusBID:105254
https://www.debian.org/security/2018/dsa-4290
https://lists.debian.org/debian-lts-announce/2018/09/msg00011.html
https://gnunet.org/bugs/view.php?id=5405
https://gnunet.org/git/libextractor.git/commit/?id=24c8d489797499c0331f4d1039e357ece1ae98a7
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.