cbcvebase.
CVE-2022-25308
published 2022-09-06

CVE-2022-25308: A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianfribidi< fribidi 1.0.8-2.1 (bookworm)fribidi 1.0.8-2.1 (bookworm)
gnufribidi< 1.0.121.0.12
gnufribidi
gnufribidi>= 0 < 1.0.8-2+deb11u11.0.8-2+deb11u1
gnufribidi>= 0 < 1.0.8-2.11.0.8-2.1
gnufribidi>= 0 < 1.0.8-2.11.0.8-2.1
gnufribidi>= 0 < 1.0.8-2.11.0.8-2.1
gnufribidi>= 0 < 0.19.7-2ubuntu0.10.19.7-2ubuntu0.1
gnufribidi>= 0 < 1.0.8-2ubuntu0.11.0.8-2ubuntu0.1
gnufribidi>= 0 < 1.0.8-2ubuntu3.11.0.8-2ubuntu3.1
gnufribidi>= 0 < 0.19.7-1ubuntu0.1~esm10.19.7-1ubuntu0.1~esm1
msrccbl2_fribidi_1.0.12-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH