Your submission was sent successfully! Close

CVE-2022-25308

Published: 22 February 2022

A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
fribidi
Launchpad, Ubuntu, Debian
bionic
Released (0.19.7-2ubuntu0.1)
focal
Released (1.0.8-2ubuntu0.1)
impish
Released (1.0.8-2ubuntu2.1)
jammy
Released (1.0.8-2ubuntu3.1)
trusty Ignored
(out of standard support)
upstream
Released (v1.0.12)
xenial Ignored
(out of standard support)
Patches:
upstream: https://github.com/fribidi/fribidi/commit/ad3a19e6372b1e667128ed1ea2f49919884587e1