CVE-2022-0699CRITICALCVSS 9.8fixed in shapelib 1.5.0-3 (bookworm)2022
CVE-2022-0699 [CRITICAL] CVE-2022-0699: shapelib - A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older ...
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.
Scope: local
bookworm: resolved (fixed in 1.5.0-3)
bullseye: resolved (fixed in 1.5.0-2+deb11u1)
forky: resolved (fixed in 1.5.0-3)
sid: resolved (fixed in
debian