Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18751

Опубликовано: 28 окт. 2018
Источник: redhat
CVSS3: 4

Описание

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.

Отчет

This issue affects the versions of gettext as shipped with Red Hat Enterprise Linux 7. This issue did not affect the versions of gettext as shipped with Red Hat Enterprise Linux 5 and 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gettextNot affected
Red Hat Enterprise Linux 6gettextNot affected
Red Hat Enterprise Linux 8mingw-gettextFix deferred
Red Hat Enterprise Linux 7gettextFixedRHSA-2020:113831.03.2020
Red Hat Enterprise Linux 7.6 Extended Update SupportgettextFixedRHSA-2020:284607.07.2020
Red Hat Enterprise Linux 7.7 Extended Update SupportgettextFixedRHSA-2020:248512.06.2020
Red Hat Enterprise Linux 8gettextFixedRHSA-2019:364305.11.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1647043gettext: double free in default_add_message in read-catalog.c

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.

CVSS3: 9.8
nvd
больше 6 лет назад

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.

CVSS3: 9.8
debian
больше 6 лет назад

An issue was discovered in GNU gettext 0.19.8. There is a double free ...

suse-cvrf
почти 5 лет назад

Security update for gettext-runtime

suse-cvrf
почти 5 лет назад

Security update for gettext-runtime

4 Medium

CVSS3