Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-37529

Опубликовано: 13 янв. 2022
Источник: redhat
CVSS3: 5.5

Описание

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

A double-free vulnerability was found in fig2dev in the free_stream() function of 'readpics.c'. This issue occurs due to freeing the memory for long file names. This flaw allows an attacker to pass a crafted file to fig2dev, causing a double-free fault that can lead to a denial of service.

Отчет

Red Hat Enterprise Linux is not affected by this vulnerability as Red Hat ships fig2dev v3.2.7b and lower versions whereas it affects fig2dev v3.2.8a and upper versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6transfigNot affected
Red Hat Enterprise Linux 7transfigNot affected
Red Hat Enterprise Linux 8transfigNot affected
Red Hat Enterprise Linux 9transfigNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-672
https://bugzilla.redhat.com/show_bug.cgi?id=2044569transfig: Double-free via the free_stream function in readpics.c

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

CVSS3: 5.5
nvd
около 4 лет назад

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

CVSS3: 5.5
debian
около 4 лет назад

A double-free vulnerability exists in fig2dev through 3.28a is affecte ...

github
около 4 лет назад

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

CVSS3: 5.5
fstec
около 4 лет назад

Уязвимость функции free_stream утилиты для преобразования файлов с расширением fig fig2dev , связанная с ошибкой повторного освобождения памяти, позволяющая нарушителю вызвать отказ в обслуживании

5.5 Medium

CVSS3