CVE Vulnerabilities

CVE-2021-37529

Double Free

Published: Jan 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Fig2devFig2dev_project*3.2.8a (including)
Fig2devUbuntubionic*
Fig2devUbuntufocal*
Fig2devUbuntuhirsute*
Fig2devUbuntuimpish*
Fig2devUbuntukinetic*
Fig2devUbuntulunar*
Fig2devUbuntumantic*
Fig2devUbuntutrusty*
Fig2devUbuntuupstream*
Fig2devUbuntuxenial*

Potential Mitigations

References