Candidate: CVE-2019-9035 PublicDate: 2019-02-23 12:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9035 https://github.com/tbeu/matio/issues/103 https://github.com/TeamSeri0us/pocs/tree/master/matio Description: An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function ReadNextStructField() in mat5.c. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H [9.1 CRITICAL] Patches_libmatio: upstream_libmatio: released (1.5.13-2) precise/esm_libmatio: DNE trusty_libmatio: ignored (reached end-of-life) trusty/esm_libmatio: DNE (trusty was needs-triage) xenial_libmatio: ignored (end of standard support, was needed) bionic_libmatio: needed cosmic_libmatio: ignored (reached end-of-life) disco_libmatio: ignored (reached end-of-life) eoan_libmatio: not-affected (1.5.13-3) focal_libmatio: not-affected (1.5.13-3) groovy_libmatio: not-affected (1.5.13-3) hirsute_libmatio: not-affected (1.5.13-3) impish_libmatio: not-affected (1.5.13-3) jammy_libmatio: not-affected (1.5.13-3) devel_libmatio: not-affected (1.5.13-3)