USN-7638-1
Dashboard / Vulnerabilities / USN-7638-1
USN-7638-1
Summary: libmobi vulnerabilities
Details: It was discovered that Libmobi did not correctly handle certain memory operations, which could lead to a buffer overflow. A local attacker could possibly trigger this vulnerability to cause a denial of service. (CVE-2022-1907, CVE-2022-1908) It was discovered that Libmobi could dereference a NULL pointer via the component mobi_buffer_getpointer. A local attacker could possibly trigger this vulnerability to cause a denial of service. (CVE-2022-29788)
References: https://ubuntu.com/security/notices/USN-7638-1, https://ubuntu.com/security/CVE-2022-1907, https://ubuntu.com/security/CVE-2022-1908, https://ubuntu.com/security/CVE-2022-29788
Affected packages
Package
Name: libmobi
Purl: pkg:deb/ubuntu/[email protected]+dfsg1-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy
Affected ranges
Type: ECOSYSTEM
Events:
