Candidate: CVE-2016-5637 PublicDate: 2016-07-15 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5637 http://www.kb.cert.org/vuls/id/123799 Description: The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted BPG image, related to a "type confusion" issue. Ubuntu-Description: Notes: ebarretto> This CVE doesn't have much information and it appears to be ebarretto> a duplicate of CVE-2016-8710, so we are using the information ebarretto> available on CVE-2016-8710. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_chromium-browser: upstream_chromium-browser: needs-triage precise_chromium-browser: ignored precise/esm_chromium-browser: DNE (precise was ignored) trusty_chromium-browser: not-affected (code not present) trusty/esm_chromium-browser: DNE (trusty was not-affected [code not present]) vivid/ubuntu-core_chromium-browser: DNE vivid/stable-phone-overlay_chromium-browser: DNE wily_chromium-browser: not-affected (reached end-of-life) xenial_chromium-browser: not-affected (code not present) yakkety_chromium-browser: not-affected (code not present) zesty_chromium-browser: not-affected (code not present) artful_chromium-browser: not-affected (code not present) bionic_chromium-browser: not-affected (code not present) cosmic_chromium-browser: not-affected (code not present) disco_chromium-browser: not-affected (code not present) eoan_chromium-browser: not-affected (code not present) focal_chromium-browser: not-affected (code not present) groovy_chromium-browser: not-affected (code not present) hirsute_chromium-browser: not-affected (code not present) impish_chromium-browser: not-affected (code not present) jammy_chromium-browser: not-affected (code not present) devel_chromium-browser: not-affected (code not present) Patches_oxide-qt: upstream_oxide-qt: needs-triage precise_oxide-qt: DNE precise/esm_oxide-qt: DNE trusty_oxide-qt: not-affected (code not present) trusty/esm_oxide-qt: DNE (trusty was not-affected [code not present]) vivid/ubuntu-core_oxide-qt: DNE vivid/stable-phone-overlay_oxide-qt: not-affected (code not present) wily_oxide-qt: not-affected (reached end-of-life) xenial_oxide-qt: not-affected (code not present) esm-infra/xenial_oxide-qt: not-affected (code not present) yakkety_oxide-qt: not-affected (code not present) zesty_oxide-qt: not-affected (code not present) artful_oxide-qt: not-affected (code not present) bionic_oxide-qt: DNE cosmic_oxide-qt: DNE disco_oxide-qt: DNE eoan_oxide-qt: DNE focal_oxide-qt: DNE groovy_oxide-qt: DNE hirsute_oxide-qt: DNE impish_oxide-qt: DNE jammy_oxide-qt: DNE devel_oxide-qt: DNE Patches_vlc: upstream_vlc: not-affected (code not present) precise_vlc: ignored (reached end-of-life) precise/esm_vlc: DNE (precise was needs-triage) trusty_vlc: not-affected (code not present) trusty/esm_vlc: DNE (trusty was not-affected [code not present]) vivid/stable-phone-overlay_vlc: DNE vivid/ubuntu-core_vlc: DNE wily_vlc: ignored (reached end-of-life) xenial_vlc: not-affected (code not present) yakkety_vlc: ignored (reached end-of-life) zesty_vlc: ignored (reached end-of-life) artful_vlc: ignored (reached end-of-life) bionic_vlc: not-affected (code not present) cosmic_vlc: not-affected (code not present) disco_vlc: not-affected (code not present) eoan_vlc: not-affected (code not present) focal_vlc: not-affected (code not present) groovy_vlc: not-affected (code not present) hirsute_vlc: not-affected (code not present) impish_vlc: not-affected (code not present) jammy_vlc: not-affected (code not present) devel_vlc: not-affected (code not present) Patches_ffmpeg: upstream_ffmpeg: needs-triage precise_ffmpeg: DNE precise/esm_ffmpeg: DNE trusty_ffmpeg: DNE trusty/esm_ffmpeg: DNE vivid/stable-phone-overlay_ffmpeg: DNE vivid/ubuntu-core_ffmpeg: DNE wily_ffmpeg: ignored (reached end-of-life) xenial_ffmpeg: not-affected (2.6) yakkety_ffmpeg: ignored (reached end-of-life) zesty_ffmpeg: ignored (reached end-of-life) artful_ffmpeg: ignored (reached end-of-life) bionic_ffmpeg: not-affected (2.6) cosmic_ffmpeg: not-affected (2.6) disco_ffmpeg: not-affected (2.6) eoan_ffmpeg: not-affected (2.6) focal_ffmpeg: not-affected (2.6) groovy_ffmpeg: not-affected (2.6) hirsute_ffmpeg: not-affected (2.6) impish_ffmpeg: not-affected (2.6) jammy_ffmpeg: not-affected (2.6) devel_ffmpeg: not-affected (2.6) Patches_gst-libav1.0: upstream_gst-libav1.0: needs-triage precise_gst-libav1.0: DNE precise/esm_gst-libav1.0: DNE trusty_gst-libav1.0: ignored (reached end-of-life) trusty/esm_gst-libav1.0: DNE (trusty was needs-triage) vivid/stable-phone-overlay_gst-libav1.0: DNE vivid/ubuntu-core_gst-libav1.0: DNE wily_gst-libav1.0: ignored (reached end-of-life) xenial_gst-libav1.0: ignored (end of standard support, was needs-triage) yakkety_gst-libav1.0: ignored (reached end-of-life) zesty_gst-libav1.0: ignored (reached end-of-life) artful_gst-libav1.0: ignored (reached end-of-life) bionic_gst-libav1.0: needs-triage cosmic_gst-libav1.0: ignored (reached end-of-life) disco_gst-libav1.0: ignored (reached end-of-life) eoan_gst-libav1.0: ignored (reached end-of-life) focal_gst-libav1.0: needs-triage groovy_gst-libav1.0: ignored (reached end-of-life) hirsute_gst-libav1.0: ignored (reached end-of-life) impish_gst-libav1.0: needs-triage jammy_gst-libav1.0: needs-triage devel_gst-libav1.0: needs-triage