Candidate: CVE-2020-13999 PublicDate: 2020-06-15 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13999 http://libemf.sourceforge.net/index.html https://sourceforge.net/p/libemf/code/HEAD/tree/ https://sourceforge.net/p/libemf/news/2020/06/release-of-libemf-1013/ https://sourceforge.net/projects/libemf/ Description: ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_libemf: upstream_libemf: needs-triage precise/esm_libemf: DNE trusty_libemf: ignored (out of standard support) trusty/esm_libemf: DNE xenial_libemf: DNE bionic_libemf: needs-triage eoan_libemf: ignored (reached end-of-life) focal_libemf: needs-triage groovy_libemf: not-affected (1.0.13-2) hirsute_libemf: not-affected (1.0.13-2) impish_libemf: not-affected (1.0.13-2) jammy_libemf: not-affected (1.0.13-2) devel_libemf: not-affected (1.0.13-2)