GNU Libextractor is prone to multiple security vulnerabilities.
1. A remote denial-of-service vulnerability
2. An out-of-bound read access vulnerability
Attackers can exploit these issues to crash the application denying service to legitimate users or disclose sensitive information that may aid in further attacks.
Information
CVE-2018-20431
GNU libextractor 1.7
GNU libextractor 1.6
GNU libextractor 1.4
Exploit
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information.
References: