Description
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29492 | There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it. |
References
History
No history.
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-08-04T03:30:38.667Z
Reserved: 2021-10-15T00:00:00.000Z
Link: CVE-2021-42523
No data.
Status : Modified
Published: 2022-08-25T18:15:09.260
Modified: 2024-11-21T06:27:43.930
Link: CVE-2021-42523
OpenCVE Enrichment
No data.
EUVD