Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
fontconfig 资源管理错误漏洞
Vulnerability Description
fontconfig是freedesktop开源的一种与字体相关的计算机程序库。 fontconfig 2.12.1之前版本存在资源管理错误漏洞,该漏洞源于程序没有验证偏移量。本地攻击者可借助特制的缓存文件利用该漏洞触发任意释放调用,实施双重释放攻击,执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A