PublicDateAtUSN: 2018-10-31 22:29:00 UTC Candidate: CVE-2016-6328 PublicDate: 2018-10-31 22:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6328 https://ubuntu.com/security/notices/USN-4277-1 Description: A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data). Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=873022 Priority: low Discovered-by: Liu Bingchang Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H [8.1 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H [8.1 HIGH] Patches_libexif: upstream: http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/libexif/pentax/mnote-pentax-entry.c?r1=1.26&r2=1.27 upstream_libexif: needed precise/esm_libexif: released (0.6.20-2ubuntu0.2) trusty_libexif: ignored (reached end-of-life) trusty/esm_libexif: released (0.6.21-1ubuntu1+esm1) vivid/ubuntu-core_libexif: DNE xenial_libexif: released (0.6.21-2ubuntu0.1) esm-infra/xenial_libexif: released (0.6.21-2ubuntu0.1) zesty_libexif: ignored (reached end-of-life) artful_libexif: ignored (reached end-of-life) bionic_libexif: not-affected (0.6.21-4) cosmic_libexif: ignored (reached end-of-life) disco_libexif: not-affected (0.6.21-5.1) eoan_libexif: not-affected (0.6.21-5.1) devel_libexif: not-affected (0.6.21-5.1)