CVE-2016-5384
published 2016-08-13CVE-2016-5384: fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and…
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
33.1th percentile
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | fontconfig | < fontconfig 2.11.0-6.5 (bookworm) | fontconfig 2.11.0-6.5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fontconfig_project | fontconfig | < 2.12.1 | 2.12.1 |
| fontconfig_project | fontconfig | >= 0 < 2.11.0-6.5 | 2.11.0-6.5 |
| fontconfig_project | fontconfig | >= 0 < 2.11.0-6.5 | 2.11.0-6.5 |
| fontconfig_project | fontconfig | >= 0 < 2.11.0-6.5 | 2.11.0-6.5 |
| fontconfig_project | fontconfig | >= 0 < 2.11.0-6.5 | 2.11.0-6.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Fontconfig vulnerability
vendor_ubuntu·2016-08-17
CVE-2016-5384 Fontconfig vulnerability
Title: Fontconfig vulnerability
Summary: Fontconfig be made to crash or run programs if it opened a specially
crafted file.
Tobias Stoeckmann discovered that Fontconfig incorrectly handled cache
files. A local attacker could possibly use this issue with a specially
crafted cache file to elevate privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
fontconfig: Possible double free due to insufficiently validated cache files
vendor_redhat·2016-08-05·CVSS 7.8
CVE-2016-5384 [HIGH] CWE-20 fontconfig: Possible double free due to insufficiently validated cache files
fontconfig: Possible double free due to insufficiently validated cache files
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
It was found that cache files were insufficiently validated in fontconfig. A local attacker could create a specially crafted cache file to trigger arbitrary free() calls, which in turn could lead to arbitrary code execution.
Package: fontconfig (Red Hat Enterprise Linux 5) - Will not fix
Package: fontconfig (Red Hat Enterprise Linux 6) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Will not fix
Debian
CVE-2016-5384: fontconfig - fontconfig before 2.12.1 does not validate offsets, which allows local users to ...
vendor_debian·2016·CVSS 7.8
CVE-2016-5384 [HIGH] CVE-2016-5384: fontconfig - fontconfig before 2.12.1 does not validate offsets, which allows local users to ...
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
Scope: local
bookworm: resolved (fixed in 2.11.0-6.5)
bullseye: resolved (fixed in 2.11.0-6.5)
forky: resolved (fixed in 2.11.0-6.5)
sid: resolved (fixed in 2.11.0-6.5)
trixie: resolved (fixed in 2.11.0-6.5)
GHSA
GHSA-g839-937g-3fhv: fontconfig before 2
ghsa_unreviewed·2022-05-13
CVE-2016-5384 [HIGH] CWE-415 GHSA-g839-937g-3fhv: fontconfig before 2
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
OSV
CVE-2016-5384: fontconfig before 2
osv·2016-08-13·CVSS 7.8
CVE-2016-5384 [HIGH] CVE-2016-5384: fontconfig before 2
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8979 dcmtk: Wrong length of ACSE structures can cause remote overflows/underflows
bugzilla·2016-12-19·CVSS 7.5
CVE-2015-8979 [HIGH] CVE-2015-8979 dcmtk: Wrong length of ACSE structures can cause remote overflows/underflows
CVE-2015-8979 dcmtk: Wrong length of ACSE structures can cause remote overflows/underflows
At several places in the code a wrong length of ACSE data structures received over the network can cause overflows or underflows when processing those data structures. Related checks have been added at various places in order to prevent such (possible) attacks. The bug will affect all DCMTK-based server applications that accept incoming DICOM network connections.
According to the reports only <= 3.6.0 versions are affected.
References:
http://seclists.org/oss-sec/2016/q4/700
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5384.php
Upstream patch:
https://github.com/commontk/DCMTK/commit/1b6bb76
Bugzilla
CVE-2016-5384 mingw-fontconfig: fontconfig: Possible double free due to insufficiently validated cache files [epel-7]
bugzilla·2016-08-05·CVSS 7.8
CVE-2016-5384 [HIGH] CVE-2016-5384 mingw-fontconfig: fontconfig: Possible double free due to insufficiently validated cache files [epel-7]
CVE-2016-5384 mingw-fontconfig: fontconfig: Possible double free due to insufficiently validated cache files [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automa
Bugzilla
CVE-2016-5384 mingw-fontconfig: fontconfig: Possible double free due to insufficiently validated cache files [fedora-all]
bugzilla·2016-08-05·CVSS 7.8
CVE-2016-5384 [HIGH] CVE-2016-5384 mingw-fontconfig: fontconfig: Possible double free due to insufficiently validated cache files [fedora-all]
CVE-2016-5384 mingw-fontconfig: fontconfig: Possible double free due to insufficiently validated cache files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2016-5384 fontconfig: Possible double free due to insufficiently validated cache files [fedora-all]
bugzilla·2016-08-05·CVSS 7.8
CVE-2016-5384 [HIGH] CVE-2016-5384 fontconfig: Possible double free due to insufficiently validated cache files [fedora-all]
CVE-2016-5384 fontconfig: Possible double free due to insufficiently validated cache files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2016-5384 fontconfig: Possible double free due to insufficiently validated cache files
bugzilla·2016-06-28·CVSS 7.8
CVE-2016-5384 [HIGH] CVE-2016-5384 fontconfig: Possible double free due to insufficiently validated cache files
CVE-2016-5384 fontconfig: Possible double free due to insufficiently validated cache files
It was reported that offsets contained in cache files aren't checked if they're in legal ranges or are pointers at all. The lack of validation allows an attacker to trigger arbitrary free() calls, which in turn allows double free attacks and therefore arbitrary code execution. When used with setuid binaries using crafted cachefiles, privilege escalation is possible.
Discussion:
Acknowledgments:
Name: Tobias Stoeckmann
---
The fix has been pushed to the upstream git:
https://lists.freedesktop.org/archives/fontconfig/2016-August/005792.html
---
Public via https://lists.freedesktop.org/archives/fontconfig/2016-August/005792.html
---
BTW no bugs for Fedora?
---
Created mingw-fontconfig tracki
http://rhn.redhat.com/errata/RHSA-2016-2601.htmlhttp://www.debian.org/security/2016/dsa-3644http://www.securityfocus.com/bid/92339http://www.ubuntu.com/usn/USN-3063-1https://cgit.freedesktop.org/fontconfig/commit/?id=7a4a5bd7897d216f0794ca9dbce0a4a5c9d14940https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CJ45VRAMCIISHOVKFVOQYQUSTUJP7FC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGOS4YYB7UYAWX5AEXJZHDIX4ZMSXSW5/https://lists.freedesktop.org/archives/fontconfig/2016-August/005792.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2601.htmlhttp://www.debian.org/security/2016/dsa-3644http://www.securityfocus.com/bid/92339http://www.ubuntu.com/usn/USN-3063-1https://cgit.freedesktop.org/fontconfig/commit/?id=7a4a5bd7897d216f0794ca9dbce0a4a5c9d14940https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CJ45VRAMCIISHOVKFVOQYQUSTUJP7FC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGOS4YYB7UYAWX5AEXJZHDIX4ZMSXSW5/https://lists.freedesktop.org/archives/fontconfig/2016-August/005792.html
2016-08-13
Published