Candidate: CVE-2018-13794 PublicDate: 2018-07-09 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13794 https://github.com/posva/catimg/issues/34 Description: A heap-based buffer overflow exists in stbi__bmp_load_cont in stb_image.h in catimg 2.4.0. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_catimg: upstream_catimg: needs-triage precise/esm_catimg: DNE trusty_catimg: DNE trusty/esm_catimg: DNE xenial_catimg: DNE artful_catimg: ignored (reached end-of-life) bionic_catimg: needs-triage cosmic_catimg: ignored (reached end-of-life) disco_catimg: not-affected (2.5.0-1) eoan_catimg: not-affected (2.5.0-1) focal_catimg: not-affected (2.5.0-1) groovy_catimg: not-affected (2.5.0-1) hirsute_catimg: not-affected (2.5.0-1) impish_catimg: not-affected (2.5.0-1) jammy_catimg: not-affected (2.5.0-1) devel_catimg: not-affected (2.5.0-1)