Candidate: CVE-2019-1010057 PublicDate: 2019-07-16 13:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010057 https://github.com/phaag/nfdump/issues/104 https://github.com/phaag/nfdump/commit/9f0fe9563366f62a71d34c92229da3432ec5cf0e Description: nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdump must read and process a specially crafted file. The fixed version is: after commit 9f0fe9563366f62a71d34c92229da3432ec5cf0e. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_nfdump: upstream_nfdump: released (1.6.17-1) precise/esm_nfdump: DNE trusty_nfdump: ignored (out of standard support) trusty/esm_nfdump: DNE xenial_nfdump: not-affected (code not present) bionic_nfdump: needed disco_nfdump: released (1.6.17-1) eoan_nfdump: released (1.6.17-1) focal_nfdump: released (1.6.17-1) groovy_nfdump: released (1.6.17-1) hirsute_nfdump: released (1.6.17-1) impish_nfdump: released (1.6.17-1) jammy_nfdump: released (1.6.17-1) devel_nfdump: released (1.6.17-1)