JLSEC-2025-174
Dashboard / Vulnerabilities / JLSEC-2025-174
Summary: An issue was discovered in GNU gettext 0.19.8
Details: An issue was discovered in GNU gettext 0.19.8. There is a double free in `default_add_message` in read-catalog.c, related to an invalid free in `po_gram_parse` in po-gram-gen.y, as demonstrated by lt-msgfmt.
References: http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00061.html, http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00065.html, http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00025.html, https://access.redhat.com/errata/RHSA-2019:3643, https://github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/doublefree, https://github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/heapcorruption, https://usn.ubuntu.com/3815-1/, https://usn.ubuntu.com/3815-2/
Affected packages
Package
Name: Gettext_jll
Purl: pkg:julia/Gettext_jll?uuid=78b55507-aeef-58d4-861c-77aaff3498b1
Affected ranges
Type: SEMVER
Events:
