HIGH
GNOME gvdb gvdb-builder.c gvdb_table_write_contents_async use after free
Published Dec 26, 2022
8.8
HIGHCVSS 3.1
EPSS 0.79%
Description
A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gvdb-builder.c. The manipulation leads to use after free. It is possible to initiate the attack remotely. The name of the patch is d83587b2a364eb9a9a53be7e6a708074e252de14. It is recommended to apply a patch to fix this issue. The identifier VDB-216789 was assigned to this vulnerability.
Affected products
- < 2019-06-27
No data.
Red Hat Enterprise Linux 9
dconf
Not affected
Red Hat Enterprise Linux 9
glib2
Not affected
Red Hat Enterprise Linux 9
libreoffice:flatpak/dconf
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | dconf | Not affected | n/a |
| Red Hat Enterprise Linux 9 | glib2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libreoffice:flatpak/dconf | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2019-25085 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2156440 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11526 Advisory
- https://github.com/GNOME/gvdb/commit/d83587b2a364eb9a9a53be7e6a708074e252de14 patchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-25085
- https://vuldb.com/?ctiid.216789 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.216789 vdb-entrytechnical-descriptionThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-25085
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-25085 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2156440 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11526 | Advisory | |
| https://github.com/GNOME/gvdb/commit/d83587b2a364eb9a9a53be7e6a708074e252de14 | patchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-25085 | ||
| https://vuldb.com/?ctiid.216789 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.216789 | vdb-entrytechnical-descriptionThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-25085 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 26, 2022
Updated Aug 5, 2024
Reserved Dec 26, 2022
Link CVE-2019-25085
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-11526 Assigner VulDB
Published Dec 26, 2022
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-11526