It was discovered that Scilab did not properly sanitize XML inputs. An atacker could use a crafted XML file to cause a denial of service or possibly execute arbitrary code.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "scilab", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-cli", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-data", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-doc", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-doc-fr", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-doc-ja", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-doc-pt-br", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-full-bin", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-full-bin-dbg", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-full-bin-dbgsym", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-include", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-include-dbgsym", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-minimal-bin", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-minimal-bin-dbg", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-minimal-bin-dbgsym", "binary_version": "5.5.2-2ubuntu3+esm1" }, { "binary_name": "scilab-test", "binary_version": "5.5.2-2ubuntu3+esm1" } ] }