PT-2022-6931 · Colord+4 · Colord+4
Published
2022-02-28
·
Updated
2025-12-18
·
CVE-2021-42523
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
colord (affected versions not specified)
Description
The issue is related to two Information Disclosure vulnerabilities in colord. These vulnerabilities are located in colord/src/cd-device-db.c and colord/src/cd-profile-db.c. The problem arises because the
err msg of sqlite3 exec is not released after use, contrary to the requirements of libxml2, which states that the caller must release it. This could allow a remote attacker to gain unauthorized access to protected information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Leak
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Suse
Colord