Oval Definition:oval:com.ubuntu.xenial:def:2017178800000000
Revision Date:2017-12-27Version:1
Title:CVE-2017-17880 on Ubuntu 16.04 LTS (xenial) - low.
Description:In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to a WEBP_DECODER_ABI_VERSION check.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-17880
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • NOT imagemagick package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT imagemagick-6.q16 package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT imagemagick-common package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libimage-magick-perl package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libimage-magick-q16-perl package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagick++-6-headers package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagick++-6.q16-5v5 package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagickcore-6-arch-config package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagickcore-6-headers package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagickcore-6.q16-2 package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagickcore-6.q16-2-extra package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagickwand-6-headers package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT libmagickwand-6.q16-2 package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • OR NOT perlmagick package in xenial, while related to the CVE in some way, is not affected (note: 'code not built').
  • BACK