CVE-2021-42523
Dashboard / Vulnerabilities / CVE-2021-42523
CVE-2021-42523
Published: 25 Aug 2022Last Modified: 9 Jul 2026
Summary:
Details: There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.
References: https://github.com/hughsie/colord/issues/110
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 233e642f730e46e026c1fe45d36ea298de1e00fe
Fixed -None
Affected versions
1.4.4
1.4.5
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
