PublicDateAtUSN: 2019-09-08 03:15:00 UTC Candidate: CVE-2019-16091 PublicDate: 2019-09-08 03:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16091 https://github.com/hoene/libmysofa/compare/f571522...e07edb3 https://github.com/hoene/libmysofa/commit/af9bbedcba2cd125fe36fa9058bd91303643472b https://github.com/hoene/libmysofa/commit/e07edb39e9ecc796127cd748ada4a4bac88cb5d2 https://ubuntu.com/security/notices/USN-4473-1 Description: Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=939735 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_libmysofa: upstream_libmysofa: needs-triage precise/esm_libmysofa: DNE trusty_libmysofa: ignored (out of standard support) trusty/esm_libmysofa: DNE xenial_libmysofa: DNE bionic_libmysofa: released (0.6~dfsg0-3+deb10u1build1) disco_libmysofa: ignored (reached end-of-life) eoan_libmysofa: ignored (reached end-of-life) focal_libmysofa: not-affected (0.8~dfsg0-1) devel_libmysofa: not-affected (0.8~dfsg0-1)