Candidate: CVE-2015-7508 PublicDate: 2020-02-12 03:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7508 Description: Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libnsgif: upstream_libnsgif: needs-triage precise_libnsgif: ignored (reached end-of-life) precise/esm_libnsgif: DNE (precise was needed) trusty_libnsgif: ignored (reached end-of-life) trusty/esm_libnsgif: DNE (trusty was needed) vivid_libnsgif: ignored (reached end-of-life) vivid/stable-phone-overlay_libnsgif: DNE vivid/ubuntu-core_libnsgif: DNE wily_libnsgif: ignored (reached end-of-life) xenial_libnsgif: DNE yakkety_libnsgif: DNE zesty_libnsgif: DNE artful_libnsgif: DNE bionic_libnsgif: DNE cosmic_libnsgif: DNE disco_libnsgif: DNE devel_libnsgif: DNE