CVE Vulnerabilities

CVE-2021-42613

Double Free

Published: May 24, 2022 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Halibut Halibut_project 1.2 (including) 1.2 (including)
Halibut Ubuntu bionic *
Halibut Ubuntu impish *
Halibut Ubuntu kinetic *
Halibut Ubuntu lunar *
Halibut Ubuntu mantic *

Potential Mitigations

References