CVE-2022-25310

Improper Input Validation in conan/fribidi

Identifiers

CVE-2022-25310

Package Slug

conan/fribidi

Vulnerability

Improper Input Validation

Description

A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.

Affected Versions

All versions before 1.0.12

Solution

Upgrade to version 1.0.12 or above.

Last Modified

2022-09-12

source