There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'errmsg' of 'sqlite3exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.
{
"binaries": [
{
"binary_version": "1.4.6-1",
"binary_name": "colord"
},
{
"binary_version": "1.4.6-1",
"binary_name": "colord-data"
},
{
"binary_version": "1.4.6-1",
"binary_name": "colord-dbgsym"
},
{
"binary_version": "1.4.6-1",
"binary_name": "colord-tests"
},
{
"binary_version": "1.4.6-1",
"binary_name": "colord-tests-dbgsym"
},
{
"binary_version": "1.4.6-1",
"binary_name": "gir1.2-colord-1.0"
},
{
"binary_version": "1.4.6-1",
"binary_name": "gir1.2-colorhug-1.0"
},
{
"binary_version": "1.4.6-1",
"binary_name": "libcolord-dev"
},
{
"binary_version": "1.4.6-1",
"binary_name": "libcolord2"
},
{
"binary_version": "1.4.6-1",
"binary_name": "libcolord2-dbgsym"
},
{
"binary_version": "1.4.6-1",
"binary_name": "libcolorhug-dev"
},
{
"binary_version": "1.4.6-1",
"binary_name": "libcolorhug2"
},
{
"binary_version": "1.4.6-1",
"binary_name": "libcolorhug2-dbgsym"
}
],
"availability": "No subscription required"
}