PublicDateAtUSN: 2021-10-08 20:15:00 UTC Candidate: CVE-2020-22617 PublicDate: 2021-10-08 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22617 https://tracker.ardour.org/view.php?id=7926 https://github.com/Ardour/ardour/commit/96daa4036a https://ubuntu.com/security/notices/USN-5110-1 Description: Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_ardour: upstream: https://github.com/Ardour/ardour/commit/96daa4036a425ff3f23a7dfcba57bfb0f942bec6 (6.0-pre1) upstream_ardour: released (1:6.0.0~ds0-1) trusty_ardour: ignored (out of standard support) trusty/esm_ardour: DNE xenial_ardour: ignored (out of standard support) bionic_ardour: released (1:5.12.0-3ubuntu0.1) focal_ardour: released (1:5.12.0-3ubuntu4.1) hirsute_ardour: not-affected (1:6.6.0+ds0-0ubuntu1) impish_ardour: not-affected jammy_ardour: not-affected devel_ardour: not-affected