There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade colord | Jul 30, 2024 | Aug 25, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade colord-libs | Nov 3, 2022 | Aug 25, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade compat-libcolord1 | Mar 9, 2023 | Aug 25, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade colord-libsUpgrade colord | Jun 9, 2023 | Aug 25, 2022 |
| Suse | — | Upgrade colordUpgrade libcolord-develUpgrade typelib-1_0-ColorHug-1_0Upgrade typelib-1_0-Colord-1_0Upgrade libcolorhug2Upgrade colord-color-profilesUpgrade libcolord2-32bitUpgrade colord-langUpgrade libcolord2 | Oct 26, 2022 | Aug 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub