There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.
{
"binaries": [
{
"binary_version": "0.3.0-2",
"binary_name": "gir1.2-gxps-0.1"
},
{
"binary_version": "0.3.0-2",
"binary_name": "libgxps-dev"
},
{
"binary_version": "0.3.0-2",
"binary_name": "libgxps-doc"
},
{
"binary_version": "0.3.0-2",
"binary_name": "libgxps-utils"
},
{
"binary_version": "0.3.0-2",
"binary_name": "libgxps-utils-dbgsym"
},
{
"binary_version": "0.3.0-2",
"binary_name": "libgxps2"
},
{
"binary_version": "0.3.0-2",
"binary_name": "libgxps2-dbgsym"
}
],
"availability": "No subscription required"
}