GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function processmetadata() in plugins/ole2extractor.c.