The liblnkdatastringgetutf8stringsize function in liblnkdatastring.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub
{
"binaries": [
{
"binary_name": "liblnk-dev",
"binary_version": "20171101-1"
},
{
"binary_name": "liblnk-utils",
"binary_version": "20171101-1"
},
{
"binary_name": "liblnk1",
"binary_version": "20171101-1"
},
{
"binary_name": "python-liblnk",
"binary_version": "20171101-1"
},
{
"binary_name": "python3-liblnk",
"binary_version": "20171101-1"
}
]
}