Vulnerability Bulletins |
DSA-3644 fontconfig - security update |
|
| Affected software | Debian |
|
Tobias Stoeckmann discovered that cache files are insufficientlyvalidated in fontconfig, a generic font configuration library. Anattacker can trigger arbitrary free() calls, which in turn allows doublefree attacks and therefore arbitrary code execution. In combination withsetuid binaries using crafted cache files, this could allow privilegeescalation. More info: https://www.debian.org/security/2016/dsa-3644 |
|






