Heap-based Buffer Over-read in GNU Libextractor Affects Multiple Versions
CVE-2019-15531
6.5MEDIUM
What is CVE-2019-15531?
GNU Libextractor, up to version 1.9, has a vulnerability that can lead to a heap-based buffer over-read in the EXTRACTOR_dvi_extract_method function located in plugins/dvi_extractor.c. This issue could potentially allow attackers to read sensitive data or execute arbitrary code. Users of vulnerable versions are encouraged to update to the latest secure release to mitigate this risk.