[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.4] fontconfig: Possible double free due to insufficiently validated cache files (CVE-2016-5384)

ID: oval:org.secpod.oval:def:1800228Date: (C)2018-03-29   (M)2023-02-20
Class: PATCHFamily: unix




It was reported that offsets contained in cache files aren"t checked if they"re in legal ranges or are pointers at all. The lack of validation allows an attacker to trigger arbitrary free calls, which in turn allows double free attacks and therefore arbitrary code execution. When used with setuid binaries using crafted cache files, privilege escalation is possible..

Platform:
Alpine Linux 3.4
Product:
fontconfig
Reference:
6024
CVE-2016-5384
CVE    1
CVE-2016-5384
CPE    3
cpe:/a:fontconfig_project:fontconfig
cpe:/a:fontconfig_project:fontconfig:2.12
cpe:/o:alpinelinux:alpine_linux:3.4

© SecPod Technologies