Candidate: CVE-2017-6962 PublicDate: 2017-03-17 09:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6962 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854447 Description: An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer overflow. This is related to the read_chunk function making an unchecked addition of 12. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854447 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_apng2gif: upstream_apng2gif: released (1.8-0.1) precise_apng2gif: ignored (reached end-of-life) precise/esm_apng2gif: DNE (precise was needs-triage) trusty_apng2gif: ignored (reached end-of-life) trusty/esm_apng2gif: DNE (trusty was needs-triage) vivid/stable-phone-overlay_apng2gif: DNE vivid/ubuntu-core_apng2gif: DNE xenial_apng2gif: not-affected (code not present) yakkety_apng2gif: ignored (reached end-of-life) zesty_apng2gif: ignored (reached end-of-life) artful_apng2gif: ignored (reached end-of-life) bionic_apng2gif: needed cosmic_apng2gif: ignored (reached end-of-life) disco_apng2gif: released (1.8-0.1) eoan_apng2gif: released (1.8-0.1) focal_apng2gif: released (1.8-0.1) groovy_apng2gif: released (1.8-0.1) hirsute_apng2gif: released (1.8-0.1) impish_apng2gif: released (1.8-0.1) jammy_apng2gif: released (1.8-0.1) devel_apng2gif: released (1.8-0.1)