An error within the tar_directory_for_file() function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libgsf | Gnome | * | 1.14.40 (including) |
Libgsf | Ubuntu | esm-apps/xenial | * |
Libgsf | Ubuntu | esm-infra-legacy/trusty | * |
Libgsf | Ubuntu | precise | * |
Libgsf | Ubuntu | trusty | * |
Libgsf | Ubuntu | trusty/esm | * |
Libgsf | Ubuntu | upstream | * |
Libgsf | Ubuntu | xenial | * |
Libgsf | Ubuntu | yakkety | * |