CVE-2022-25309 is a heap-based buffer overflow vulnerability in the Fribidi package, specifically affecting the fribidi_cap_rtl_to_unicode() function. This flaw allows an unauthenticated attacker to cause a denial of service by tricking a user into processing a specially crafted file with the '--caprtl' option, impacting GNU and Red Hat Enterprise Linux distributions and their Fribidi packages. Rated as MEDIUM severity (CVSS 5.5), the attack requires local access and user interaction, but has a high impact on availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting low immediate risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.12CPE matchmatch criteria | cpe:2.3:a:gnu:fribidi:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option leading to a crash and causing a denial of service.
Sep 13, 2022fribidi: Heap-buffer-overflow in fribidi_cap_rtl_to_unicode
Dec 22, 2021