Candidate: CVE-2017-12142 PublicDate: 2017-08-02 05:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12142 https://github.com/Yeraze/ytnef/issues/49 https://somevulnsofadlab.blogspot.com/2017/07/ytnefinvalid-memory-read-in-swapdword.html Description: In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file. Ubuntu-Description: Notes: leosilva> the issue resides in ytnefprint/main.c that is not present leosilva> in trusty. Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_libytnef: other: https://github.com/Yeraze/ytnef/commit/35dc50190aac54947bafb3d84ab7727e940c6236 upstream_libytnef: released (1.9.3-1) precise/esm_libytnef: DNE trusty_libytnef: not-affected (code not present) trusty/esm_libytnef: DNE (trusty was not-affected [code not present]) vivid/ubuntu-core_libytnef: DNE xenial_libytnef: ignored (end of standard support, was needed) zesty_libytnef: ignored (reached end-of-life) artful_libytnef: ignored (reached end-of-life) bionic_libytnef: needed cosmic_libytnef: ignored (reached end-of-life) disco_libytnef: not-affected (1.9.3-1) eoan_libytnef: not-affected (1.9.3-1) focal_libytnef: not-affected (1.9.3-1) groovy_libytnef: not-affected (1.9.3-1) hirsute_libytnef: not-affected (1.9.3-1) impish_libytnef: not-affected (1.9.3-1) jammy_libytnef: not-affected (1.9.3-1) devel_libytnef: not-affected (1.9.3-1)