There are two Information Disclosure vulnerabilities in colord, and they
lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c
separately. They exist because the 'err_msg' of 'sqlite3_exec' is not
releasing after use, while libxml2 emphasizes that the caller needs to
release it. (CVE-2021-42523)
- https://bugs.mageia.org/show_bug.cgi?id=30944
-
- https://www.cve.org/CVERecord?id=CVE-2021-42523
- 8/core/colord-1.4.5-1.1.mga8
Get the latest Linux and open source security news straight to your inbox.