PT-2022-6931 · Colord+4 · Colord+4

Published

2022-02-28

·

Updated

2025-12-18

·

CVE-2021-42523

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions colord (affected versions not specified)
Description The issue is related to two Information Disclosure vulnerabilities in colord. These vulnerabilities are located in colord/src/cd-device-db.c and colord/src/cd-profile-db.c. The problem arises because the err msg of sqlite3 exec is not released after use, contrary to the requirements of libxml2, which states that the caller must release it. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1389
ALT-PU-2022-3181
ALT-PU-2022-3267
AZL-10716
BDU:2023-05666
CVE-2021-42523
MGASA-2022-0366
OESA-2022-1914
OPENSUSE-SU-2022_3496-1
OPENSUSE-SU-2022_4170-1
OPENSUSE-SU-2024:12353-1
SUSE-SU-2022:3496-1
SUSE-SU-2022:4170-1
SUSE-SU-2022:4410-1
SUSE-SU-2022_3496-1
SUSE-SU-2022_4170-1
SUSE-SU-2022_4410-1
SUSE-SU-2025:20935-1
SUSE-SU-2025:20964-1
SUSE-SU-2025:3899-1
SUSE-SU-2025:3949-1
SUSE-SU-2025:4483-1
SUSE-SU-2025_3949-1

Affected Products

Alt Linux
Astra Linux
Debian
Suse
Colord