Candidate: CVE-2019-20016 PublicDate: 2019-12-27 02:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20016 https://github.com/hoene/libmysofa/commit/2e6fac6ab6156dae8e8c6f417741388084b70d6f https://github.com/hoene/libmysofa/issues/83 https://github.com/hoene/libmysofa/issues/84 Description: libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack consumption in readOHDRHeaderMessageDatatype in dataobject.c and directblockRead in fractalhead.c. NOTE: a download of v0.9 after 2019-12-06 should fully remediate this issue. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_libmysofa: upstream_libmysofa: released (0.9~dfsg0-1) precise/esm_libmysofa: DNE trusty_libmysofa: ignored (out of standard support) trusty/esm_libmysofa: DNE xenial_libmysofa: DNE bionic_libmysofa: needed disco_libmysofa: ignored (reached end-of-life) eoan_libmysofa: ignored (reached end-of-life) focal_libmysofa: not-affected (0.9~dfsg0-1) groovy_libmysofa: not-affected (0.9~dfsg0-1) hirsute_libmysofa: not-affected (0.9~dfsg0-1) impish_libmysofa: not-affected (0.9~dfsg0-1) jammy_libmysofa: not-affected (0.9~dfsg0-1) devel_libmysofa: not-affected (0.9~dfsg0-1)