An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libcdio | Gnu | * | 2.0.0 (excluding) |
Libcdio | Ubuntu | bionic | * |
Libcdio | Ubuntu | esm-infra/bionic | * |
Libcdio | Ubuntu | upstream | * |
Red Hat Enterprise Linux 7 | RedHat | libcdio-0:0.92-3.el7 | * |