bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a malformed CUE (.cue) file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/hessu/bchunk/issues/2 | |
https://lists.debian.org/debian-lts-announce/2017/11/msg00001.html | mailing list |
https://www.debian.org/security/2017/dsa-4026 | third party advisory vendor advisory |
https://github.com/extramaster/bchunk/issues/4 | patch third party advisory issue tracking |