CVE-2017-17440 describes a denial-of-service vulnerability in GNU Libextractor 1.6, affecting its ability to process various multimedia file formats like GIF, IT, NSFE, S3M, SID, and XM. An unauthenticated remote attacker can trigger a NULL pointer dereference and application crash by enticing a user to open a specially crafted file, leading to high availability impact. While the CVSS score is 6.5 (Medium), indicating a network-based attack with user interaction, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6CPE matchmatch criteria | cpe:2.3:a:gnu:libextractor:1.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.