CVE-2016-5384

HIGH

Fedora < 2.12.1 - Double Free

Title source: rule

Description

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 41.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status draft

Affected Products (7)

fedoraproject/fedora
fedoraproject/fedora
fontconfig_project/fontconfig < 2.12.1
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux

Timeline

Published Aug 13, 2016
Tracked Since Feb 18, 2026