Candidate: CVE-2020-11866 PublicDate: 2020-05-11 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11866 https://sourceforge.net/p/libemf/code/commit_browser https://sourceforge.net/p/libemf/mailman/libemf-devel/ https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/ Description: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_libemf: upstream_libemf: released (1.0.12-1) precise/esm_libemf: DNE trusty_libemf: ignored (out of standard support) trusty/esm_libemf: DNE xenial_libemf: DNE bionic_libemf: needs-triage eoan_libemf: ignored (reached end-of-life) focal_libemf: needs-triage groovy_libemf: not-affected (1.0.12-1) hirsute_libemf: not-affected (1.0.12-1) impish_libemf: not-affected (1.0.12-1) jammy_libemf: not-affected (1.0.12-1) devel_libemf: not-affected (1.0.12-1)