Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Ubuntu: USN-4270-1 Medium: Libjpg Denial Of Service Vulnerability

debian
Calendar Grey April 1, 2018
Debian Logo
Inadequate input validation in libevt poses risks of potential remote code execution or service interruption. Immediate update advised.
It was discovered that insufficient input sanitising in libevt, a library to access the Windows Event Log (EVT) format, could result in denial of service or the execution of arbitr...

Summary

It was discovered that insufficient input sanitising in libevt, a library
to access the Windows Event Log (EVT) format, could result in denial of
service or the execution of arbitrary code if a malformed EVT file is
processed.

For the stable distribution (stretch), this problem has been fixed in
version 20170120-1+deb9u1.

We recommend that you upgrade your libevt packages.

For the detailed security status of libevt please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libevt

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
medium
Lowest
Low
Medium
High
Critical

Package: libevt
CVE ID: CVE-2018-8754

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here