Vulnerability Description
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedoraproject | Fedora | 23 |
| Fontconfig Project | Fontconfig | < 2.12.1 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2016-2601.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3644Third Party Advisory
- http://www.securityfocus.com/bid/92339Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3063-1Third Party Advisory
- https://cgit.freedesktop.org/fontconfig/commit/?id=7a4a5bd7897d216f0794ca9dbce0aPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.freedesktop.org/archives/fontconfig/2016-August/005792.htmlMailing ListPatchThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2601.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3644Third Party Advisory
- http://www.securityfocus.com/bid/92339Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3063-1Third Party Advisory
- https://cgit.freedesktop.org/fontconfig/commit/?id=7a4a5bd7897d216f0794ca9dbce0aPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2016-5384?
CVE-2016-5384 is a vulnerability with a CVSS score of 7.8 (HIGH). fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache...
How severe is CVE-2016-5384?
CVE-2016-5384 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5384?
Check the references section above for vendor advisories and patch information. Affected products include: Fedoraproject Fedora, Fontconfig Project Fontconfig, Debian Debian Linux, Canonical Ubuntu Linux.