Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5384

Опубликовано: 13 авг. 2016
Источник: debian

Описание

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fontconfigfixed2.11.0-6.5package

Примечания

  • https://lists.freedesktop.org/archives/fontconfig/2016-August/005792.html

  • Fixed by: https://cgit.freedesktop.org/fontconfig/commit/?id=7a4a5bd7897d216f0794ca9dbce0a4a5c9d14940 (2.12.1)

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

CVSS3: 4.5
redhat
больше 9 лет назад

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

CVSS3: 7.8
nvd
больше 9 лет назад

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

suse-cvrf
около 9 лет назад

Security update for fontconfig

suse-cvrf
около 9 лет назад

Security update for fontconfig