Candidate: CVE-2017-2920 PublicDate: 2017-10-05 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2920 https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0427 Description: An memory corruption vulnerability exists in the .SVG parsing functionality of Computerinsel Photoline 20.02. A specially crafted .SVG file can cause a vulnerability resulting in memory corruption, which can potentially lead to arbitrary code execution. An attacker can send a specific .SVG file to trigger this vulnerability. Ubuntu-Description: Notes: mdeslaur> Talos advisory is not about libofx. The description in this CVE mdeslaur> may have been copied from CVE-2017-2816 by mistake. Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_libofx: upstream_libofx: needs-triage precise/esm_libofx: DNE trusty_libofx: not-affected trusty/esm_libofx: DNE (trusty was not-affected) vivid/ubuntu-core_libofx: DNE xenial_libofx: not-affected zesty_libofx: ignored (reached end-of-life) artful_libofx: ignored (reached end-of-life) bionic_libofx: not-affected cosmic_libofx: not-affected devel_libofx: not-affected