Double Free in Fontconfig - CVE-2016-5384
Published: August 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32257
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5384
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
Affected software
Fontconfig
fontconfig (Alpine package)
fontconfig (Red Hat package)
fontconfig
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Fedora
fontconfig (Alpine package)
fontconfig (Red Hat package)
fontconfig
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Fedora
How to mitigate CVE-2016-5384
Install update from vendor's website.
Fontconfig - update to 2.12.1
fontconfig (Alpine package) - update to 2.11.1-r2
fontconfig (Red Hat package) - update to 2.10.95-10.el7
fontconfig - addressed in versions 2.11.94-5.fc23, 2.11.94-7.fc24
fontconfig (Alpine package) - update to 2.11.1-r2
fontconfig (Red Hat package) - update to 2.10.95-10.el7
fontconfig - addressed in versions 2.11.94-5.fc23, 2.11.94-7.fc24
External References
- http://rhn.redhat.com/errata/RHSA-2016-2601.html
- http://www.debian.org/security/2016/dsa-3644
- http://www.securityfocus.com/bid/92339
- http://www.ubuntu.com/usn/USN-3063-1
- https://cgit.freedesktop.org/fontconfig/commit/?id=7a4a5bd7897d216f0794ca9dbce0a4a5c9d14940
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6CJ45VRAMCIISHOVKFVOQYQUSTUJP7FC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGOS4YYB7UYAWX5AEXJZHDIX4ZMSXSW5/
- https://lists.freedesktop.org/archives/fontconfig/2016-August/005792.html