Candidate: CVE-2020-6860 PublicDate: 2020-01-13 07:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6860 https://github.com/hoene/libmysofa/issues/96 https://github.com/hoene/libmysofa/commit/c31120a4ddfe3fc705cfdd74da7e884e1866da85 Description: libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libmysofa: upstream_libmysofa: needs-triage precise/esm_libmysofa: DNE trusty_libmysofa: ignored (out of standard support) trusty/esm_libmysofa: DNE xenial_libmysofa: DNE bionic_libmysofa: needed disco_libmysofa: ignored (reached end-of-life) eoan_libmysofa: ignored (reached end-of-life) focal_libmysofa: not-affected (1.0~dfsg0-1) groovy_libmysofa: not-affected (1.0~dfsg0-1) hirsute_libmysofa: not-affected (1.0~dfsg0-1) impish_libmysofa: not-affected (1.0~dfsg0-1) jammy_libmysofa: not-affected (1.0~dfsg0-1) devel_libmysofa: not-affected (1.0~dfsg0-1)