TROYANOSYVIRUS
Volver a CVEs

CVE-2016-5384

HIGH
7.8

Descripcion

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

Detalles CVE

Puntuacion CVSS v3.17.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado8/13/2016
Ultima modificacion4/12/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

canonical:ubuntu_linuxdebian:debian_linuxfedoraproject:fedorafontconfig_project:fontconfig

Debilidades (CWE)

CWE-415

Referencias

http://rhn.redhat.com/errata/RHSA-2016-2601.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2016/dsa-3644(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/92339(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-3063-1(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.