Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-42523

Опубликовано: 06 окт. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoNot affected
Red Hat Enterprise Linux 7colordNot affected
Red Hat Enterprise Linux 7compat-colord10Not affected
Red Hat Enterprise Linux 8colordNot affected
Red Hat Enterprise Linux 9colordNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2133668colord: potential memory leak, forgetting to free error message of libsqlite3 API 'sqlite3_exec' -1

EPSS

Процентиль: 32%
0.00126
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.

CVSS3: 7.5
nvd
больше 3 лет назад

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.

CVSS3: 7.5
msrc
больше 3 лет назад

There are two Information Disclosure vulnerabilities in colord and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use while libxml2 emphasizes that the caller needs to release it.

CVSS3: 7.5
debian
больше 3 лет назад

There are two Information Disclosure vulnerabilities in colord, and th ...

suse-cvrf
около 2 месяцев назад

Security update for colord

EPSS

Процентиль: 32%
0.00126
Низкий

7.5 High

CVSS3