PublicDateAtUSN: 2020-05-09 18:15:00 UTC Candidate: CVE-2020-12761 PublicDate: 2020-05-09 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12761 https://ubuntu.com/security/notices/USN-5099-1 Description: modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map. Ubuntu-Description: Notes: leosilva> introduced in later so old releases aren't affected Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960192 Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H [9.1 CRITICAL] Patches_imlib2: upstream: https://git.enlightenment.org/legacy/imlib2.git/commit/?id=c95f938ff1effaf91729c050a0f1c8684da4dd63 upstream_imlib2: needs-triage precise/esm_imlib2: DNE trusty_imlib2: ignored (out of standard support) trusty/esm_imlib2: not-affected (code not present) xenial_imlib2: ignored (end of standard support, was needs-triage) bionic_imlib2: not-affected (code not present) eoan_imlib2: ignored (reached end-of-life) focal_imlib2: released (1.6.1-1ubuntu0.1) groovy_imlib2: not-affected (1.6.1-2) hirsute_imlib2: not-affected (1.6.1-2) impish_imlib2: not-affected (1.6.1-2) jammy_imlib2: not-affected (1.6.1-2) devel_imlib2: not-affected (1.6.1-2)