SB2016081302 - Double Free in Freedesktop Fontconfig 



SB2016081302 - Double Free in Freedesktop Fontconfig

Published: August 13, 2016 Updated: July 28, 2020

Security Bulletin ID SB2016081302
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Double Free (CVE-ID: CVE-2016-5384)

The vulnerability allows a local authenticated user to execute arbitrary code.

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.


Remediation

Install update from vendor's website.