PT-2022-2350 · Fribidi+10 · Fribidi+10

Tagoh

·

Published

2021-12-22

·

Updated

2025-10-20

·

CVE-2022-25310

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fribidi (affected versions not specified)
Description A segmentation fault flaw was found in the Fribidi package, affecting the fribidi remove bidi marks() function. This issue allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service. The flaw exists due to insufficient input validation, which may allow a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

RCE

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2022:7514
ALSA-2022:8011
ALT-PU-2022-1728
ALT-PU-2022-1742
AZL-10888
BDU:2022-02658
CESA-2022_7514
CVE-2022-25310
DLA-2974-1
INFSA-2022_8011
JLSEC-2025-172
MGASA-2022-0136
OESA-2022-1923
OPENSUSE-SU-2022_1844-1
OPENSUSE-SU-2022_1898-1
RHSA-2022:7514
RHSA-2022:8011
RHSA-2022_7514
RHSA-2022_8011
RLSA-2022:7514
RLSA-2022:8011
SUSE-SU-2022:1844-1
SUSE-SU-2022:1845-1
SUSE-SU-2022:1898-1
SUSE-SU-2022:2029-1
USN-5366-1
USN-5366-2
USN-5922-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Fribidi
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu