There are two Information Disclosure vulnerabilities in...
High severity
Unreviewed
Published
Aug 26, 2022
to the GitHub Advisory Database
•
Updated Jul 17, 2023
Description
Published by the National Vulnerability Database
Aug 25, 2022
Published to the GitHub Advisory Database
Aug 26, 2022
Last updated
Jul 17, 2023
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.
References