The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.
{ "binaries": [ { "binary_name": "catdoc", "binary_version": "1:0.94.3~git20160113.dbc9ec6+dfsg-1+deb9u1build0.16.04.1" } ] }
{ "binaries": [ { "binary_name": "catdoc", "binary_version": "1:0.95-4.1" } ] }
{ "binaries": [ { "binary_name": "catdoc", "binary_version": "1:0.95-5" } ] }
{ "binaries": [ { "binary_name": "catdoc", "binary_version": "1:0.95-5build1" } ] }