An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gthumb | Feb 19, 2019 | Oct 29, 2018 |
| Suse | — | Upgrade gthumb-develUpgrade gthumb-langUpgrade gthumb | Jan 13, 2019 | Oct 29, 2018 |
| Ubuntu | — | Upgrade gthumb-data (Ubuntu Pro)Upgrade gthumb (Ubuntu Pro) | Mar 22, 2023 | Oct 29, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub