MGASA-2022-0366

Source
https://advisories.mageia.org/MGASA-2022-0366.html
Import Source
https://advisories.mageia.org/MGASA-2022-0366.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0366
Related
Published
2022-10-08T20:22:22Z
Modified
2022-10-08T19:30:50Z
Summary
Updated colord packages fix security vulnerability
Details

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'errmsg' of 'sqlite3exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it. (CVE-2021-42523)

References
Credits

Affected packages

Mageia:8 / colord

Package

Name
colord
Purl
pkg:rpm/mageia/colord?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.5-1.1.mga8

Ecosystem specific

{
    "section": "core"
}