CVE-2022-25308 is a stack-based buffer overflow vulnerability in the Fribidi package, affecting GNU and Red Hat Enterprise Linux distributions. This flaw allows an unauthenticated attacker to trigger a memory leak or denial of service by tricking a user into opening a specially crafted file. With a CVSS score of 7.8 (High), it presents a significant risk due to potential data compromise and system unavailability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.12CPE matchmatch criteria | cpe:2.3:a:gnu:fribidi:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application which leads to a possible memory leak or a denial of service.
Sep 13, 2022fribidi: Stack based buffer overflow
Dec 22, 2021