NA

CVE-2021-42523

Published: 25/08/2022 Updated: 17/07/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

colord project colord 1.4.5

colord project colord 1.4.4

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-dbc and colord/src/cd-profile-dbc separately They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it ...