In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.
{ "binaries": [ { "binary_name": "libwpd-0.10-10", "binary_version": "0.10.1-1ubuntu1" }, { "binary_name": "libwpd-dev", "binary_version": "0.10.1-1ubuntu1" }, { "binary_name": "libwpd-tools", "binary_version": "0.10.1-1ubuntu1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-19208.json"
{ "binaries": [ { "binary_name": "libwpd-0.10-10", "binary_version": "0.10.2-2" }, { "binary_name": "libwpd-dev", "binary_version": "0.10.2-2" }, { "binary_name": "libwpd-tools", "binary_version": "0.10.2-2" } ] }