SB2016080538 - Fedora 24 update for fontconfig



SB2016080538 - Fedora 24 update for fontconfig

Published: August 5, 2016 Updated: April 24, 2025

Security Bulletin ID SB2016080538
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Double Free (CVE-ID: CVE-2016-5384)

The vulnerability allows a local authenticated user to execute arbitrary code.

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.


Remediation

Install update from vendor's website.