Candidate: CVE-2016-9085 PublicDate: 2017-02-03 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9085 http://seclists.org/oss-sec/2016/q4/253 Description: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors. Ubuntu-Description: Notes: mdeslaur> issue is in file in examples directory, only used to build the mdeslaur> gif2webp tool in the webp binary package in universe. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L [3.3 LOW] Patches_libwebp: upstream: https://chromium.googlesource.com/webm/libwebp/+/e2affacc35f1df6cc3b1a9fa0ceff5ce2d0cce83 Tags_libwebp: universe-binary upstream_libwebp: needs-triage precise_libwebp: not-affected (code not present) precise/esm_libwebp: DNE (precise was not-affected [code not present]) trusty_libwebp: not-affected (code not present) trusty/esm_libwebp: not-affected (code not present) vivid/stable-phone-overlay_libwebp: ignored (reached end-of-life) vivid/ubuntu-core_libwebp: DNE xenial_libwebp: not-affected (code not present) esm-infra/xenial_libwebp: not-affected (code not present) yakkety_libwebp: ignored (reached end-of-life) zesty_libwebp: ignored (reached end-of-life) artful_libwebp: ignored (reached end-of-life) bionic_libwebp: not-affected (0.6.1-2) cosmic_libwebp: ignored (reached end-of-life) disco_libwebp: ignored (reached end-of-life) eoan_libwebp: ignored (reached end-of-life) focal_libwebp: not-affected (0.6.1-2) groovy_libwebp: not-affected (0.6.1-2) hirsute_libwebp: not-affected (0.6.1-2) devel_libwebp: not-affected (0.6.1-2)