Candidate: CVE-2019-15767 PublicDate: 2019-08-29 03:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15767 https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00004.html https://lists.gnu.org/archive/html/bug-gnu-chess/2019-08/msg00005.html Description: In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=936023 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_gnuchess: upstream_gnuchess: needs-triage precise/esm_gnuchess: DNE trusty_gnuchess: ignored (out of standard support) trusty/esm_gnuchess: DNE xenial_gnuchess: ignored (end of standard support, was needs-triage) bionic_gnuchess: needs-triage disco_gnuchess: ignored (reached end-of-life) eoan_gnuchess: ignored (reached end-of-life) focal_gnuchess: needs-triage groovy_gnuchess: ignored (reached end-of-life) hirsute_gnuchess: not-affected (6.2.7-1) impish_gnuchess: not-affected (6.2.7-1) jammy_gnuchess: not-affected (6.2.7-1) devel_gnuchess: not-affected (6.2.7-1)