CVE-2006-2458: Buffer Overflow
Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asfreadheader function in the ASF plugin (plugins/asfextractor.c), and (2) the parsetrakatom function in the QT plugin (plugins/qtextractor.c).
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2458?
CVE-2006-2458 has been classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2006-2458?
To fix CVE-2006-2458, upgrade to Libextractor version 0.5.14 or later, which addresses the identified buffer overflow issues.
What are the affected software versions for CVE-2006-2458?
CVE-2006-2458 affects Libextractor version 0.5.13 and earlier, as well as the extractor package version 0.5.
What types of attacks can leverage CVE-2006-2458?
Attackers can exploit CVE-2006-2458 through specially crafted ASF or QT files that trigger the buffer overflows.
Who is at risk regarding CVE-2006-2458?
Users and systems utilizing Libextractor versions 0.5.13 or earlier are at risk of exploitation from this vulnerability.