Double Free in gThumb - CVE-2018-18718
Published: October 31, 2018 / Updated: April 12, 2021
gThumb
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a double free error in add_themes_from_dir() method in dlg-contact-sheet.c. A remote attacker can create a specially crafted image file, trick the victim into opening it, trigger a double free error and crash the affected application.