Candidate: CVE-2019-6976 PublicDate: 2019-01-26 23:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6976 https://github.com/libvips/libvips/commit/00622428bda8d7521db8d74260b519fa41d69d0a https://github.com/libvips/libvips/releases/tag/v8.7.4 Description: libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N [5.3 MEDIUM] Patches_vips: upstream: https://github.com/libvips/libvips/commit/00622428bda8d7521db8d74260b519fa41d69d0a upstream_vips: released (8.7.4-1) precise/esm_vips: DNE trusty_vips: ignored (reached end-of-life) trusty/esm_vips: DNE (trusty was needed) xenial_vips: ignored (end of standard support, was needed) bionic_vips: needed cosmic_vips: ignored (reached end-of-life) disco_vips: not-affected (8.7.4-1) eoan_vips: not-affected (8.7.4-1) focal_vips: not-affected (8.7.4-1) groovy_vips: not-affected (8.7.4-1) hirsute_vips: not-affected (8.7.4-1) impish_vips: not-affected (8.7.4-1) jammy_vips: not-affected (8.7.4-1) devel_vips: not-affected (8.7.4-1)