[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.5] fontconfig: Possible double free due to insufficiently validated cache files (CVE-2016-5384)

ID: oval:org.secpod.oval:def:1800472Date: (C)2018-03-28   (M)2023-12-20
Class: PATCHFamily: unix




It was reported that offsets contained in cache files aren"t checked if they"re in legal ranges or are pointers at all. The lack of validation allows an attacker to trigger arbitrary free calls, which in turn allows double free attacks and therefore arbitrary code execution. When used with setuid binaries using crafted cache files, privilege escalation is possible. Reference Patch

Platform:
Alpine Linux 3.5
Product:
fontconfig
Reference:
6023
CVE-2016-5384
CVE    1
CVE-2016-5384
CPE    3
cpe:/a:fontconfig_project:fontconfig
cpe:/a:fontconfig_project:fontconfig:2.12
cpe:/o:alpinelinux:alpine_linux:3.5

© SecPod Technologies