CVE-2021-42523 describes two information disclosure vulnerabilities within the colord_project colord software, specifically in cd-device-db.c and cd-profile-db.c. These flaws stem from the failure to release the 'err_msg' buffer after sqlite3_exec calls, leading to potential exposure of sensitive data. With a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low complexity, allowing an unauthenticated attacker to achieve high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.4CPE matchmatch criteria | cpe:2.3:a:colord_project:colord:1.4.4:*:*:*:*:*:*:* | ||
1.4.5CPE matchmatch criteria | cpe:2.3:a:colord_project:colord:1.4.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
colord: potential memory leak, forgetting to free error message of libsqlite3 API 'sqlite3_exec' -1
Oct 6, 2022There are two Information Disclosure vulnerabilities in colord and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use while libxml2 emphasizes that the caller needs to release it.
Aug 9, 2022