Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g839-937g-3fhv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

EPSS

Процентиль: 42%
0.00195
Низкий

7.8 High

CVSS3

Дефекты

CWE-415

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

CVSS3: 4.5
redhat
больше 9 лет назад

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

CVSS3: 7.8
nvd
больше 9 лет назад

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

CVSS3: 7.8
debian
больше 9 лет назад

fontconfig before 2.12.1 does not validate offsets, which allows local ...

suse-cvrf
около 9 лет назад

Security update for fontconfig

EPSS

Процентиль: 42%
0.00195
Низкий

7.8 High

CVSS3

Дефекты

CWE-415