Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 8: MGASA-2022-0366 Moderate: Colord Information Disclosure Risk

mageia
Calendar Grey October 8, 2022
Dist Mageia Esm H88
The security bulletin MGASA-2022-0366 addresses a pair of information leakage vulnerabilities in colord that impact Mageia 8 platforms.
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately

Summary

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it. (CVE-2021-42523)

References

- https://bugs.mageia.org/show_bug.cgi?id=30944

-

- https://www.cve.org/CVERecord?id=CVE-2021-42523

Resolution

SRPMS

- 8/core/colord-1.4.5-1.1.mga8

Publication date: 08 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0366.html
Type: security
CVE: CVE-2021-42523

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here