Candidate: CVE-2017-1000010 PublicDate: 2017-07-17 13:18:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000010 https://packetstormsecurity.com/files/140365/Audacity-2.1.2-DLL-Hijacking.html Description: Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution. Ubuntu-Description: Notes: sbeattie> windows packaging Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_audacity: upstream_audacity: needs-triage precise/esm_audacity: DNE trusty_audacity: not-affected (windows packaging) trusty/esm_audacity: DNE (trusty was not-affected [windows packaging]) vivid/ubuntu-core_audacity: DNE xenial_audacity: not-affected (windows packaging) yakkety_audacity: not-affected (windows packaging) zesty_audacity: not-affected (windows packaging) devel_audacity: not-affected (windows packaging)