cbcvebase.
CVE-2022-25309
published 2022-09-06

CVE-2022-25309: A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial of service.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianfribidi< fribidi 1.0.8-2.1 (bookworm)fribidi 1.0.8-2.1 (bookworm)
gnufribidi< 1.0.121.0.12
gnufribidi
gnufribidi>= 0 < 1.0.8-2+deb11u11.0.8-2+deb11u1
gnufribidi>= 0 < 1.0.8-2.11.0.8-2.1
gnufribidi>= 0 < 1.0.8-2.11.0.8-2.1
gnufribidi>= 0 < 1.0.8-2.11.0.8-2.1
gnufribidi>= 0 < 0.19.7-2ubuntu0.10.19.7-2ubuntu0.1
gnufribidi>= 0 < 1.0.8-2ubuntu0.11.0.8-2ubuntu0.1
gnufribidi>= 0 < 1.0.8-2ubuntu3.11.0.8-2ubuntu3.1
gnufribidi>= 0 < 0.19.7-1ubuntu0.1~esm10.19.7-1ubuntu0.1~esm1
msrccbl2_fribidi_1.0.12-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.8HIGH