SB2016081109 - Double Free in fontconfig (Alpine package)
Published: August 11, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double Free (CVE-ID: CVE-2016-5384)
The vulnerability allows a local authenticated user to execute arbitrary code.
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=99e120348e7b8d8f1146915eb4df9a17691514fe
- https://git.alpinelinux.org/aports/commit/?id=bd9fbe8f86be75380348650dd9d7094e45b9af4e
- https://git.alpinelinux.org/aports/commit/?id=ed8947a7db077739e00779d65abe60ed81d445d6
- https://git.alpinelinux.org/aports/commit/?id=ecb97293dadc1483f2f8abfe08ea6f14e2a2be70