Your submission was sent successfully! Close

CVE-2022-25310

Published: 22 February 2022

A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.

Notes

AuthorNote
rayveldkamp
For bionic affected function is in fribidi-deprecated.c
Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
fribidi
Launchpad, Ubuntu, Debian
bionic
Released (0.19.7-2ubuntu0.1)
focal
Released (1.0.8-2ubuntu0.1)
impish
Released (1.0.8-2ubuntu2.1)
jammy
Released (1.0.8-2ubuntu3.1)
trusty Ignored
(out of standard support)
upstream
Released (v1.0.12)
xenial Ignored
(out of standard support)
Patches:
upstream: https://github.com/fribidi/fribidi/commit/175850b03e1af251d705c1d04b2b9b3c1c06e48f