Candidate: CVE-2017-6414 PublicDate: 2017-03-15 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6414 Description: Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856501 Priority: low Discovered-by: Li Qiang Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H [6.5 MEDIUM] nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H [6.5 MEDIUM] Patches_libcacard: upstream: https://cgit.freedesktop.org/spice/libcacard/commit/?id=9113dc6a303604a2d9812ac70c17d076ef11886 upstream_libcacard: released (1:2.5.0-3) precise_libcacard: DNE precise/esm_libcacard: DNE trusty_libcacard: DNE trusty/esm_libcacard: DNE vivid/stable-phone-overlay_libcacard: DNE vivid/ubuntu-core_libcacard: DNE xenial_libcacard: ignored (end of standard support, was needed) esm-infra/xenial_libcacard: needed yakkety_libcacard: ignored (reached end-of-life) zesty_libcacard: ignored (reached end-of-life) artful_libcacard: ignored (reached end-of-life) bionic_libcacard: not-affected (2.5.0-3) cosmic_libcacard: not-affected (2.5.0-3) disco_libcacard: not-affected (2.5.0-3) eoan_libcacard: not-affected (2.5.0-3) focal_libcacard: not-affected (2.5.0-3) groovy_libcacard: not-affected (2.5.0-3) hirsute_libcacard: not-affected (2.5.0-3) impish_libcacard: not-affected (2.5.0-3) jammy_libcacard: not-affected (2.5.0-3) devel_libcacard: not-affected (2.5.0-3)