PT-2016-6398 · Fontconfig+5 · Fontconfig+5

·

CVE-2016-5384

·

Publicado

2016-08-08

·

Atualizado

2023-02-12

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fontconfig versions prior to 2.12.1
Description The issue allows local users to trigger arbitrary free calls and conduct double free attacks, potentially leading to the execution of arbitrary code. This can be achieved via a crafted cache file.
Recommendations For versions prior to 2.12.1, update to version 2.12.1 or later to resolve the issue.

Correção

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1838
CESA-2016_2601
CVE-2016-5384
DLA-587-1
DSA-3644-1
MGASA-2016-0287
RHSA-2016:2601
RHSA-2016_2601
SUSE-SU-2016:2186-1
SUSE-SU-2016:2190-1
SUSE-SU-2016_2186-1
SUSE-SU-2016_2190-1
USN-3063-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Fontconfig