An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103190 | vdb entry third party advisory |
https://git.savannah.gnu.org/cgit/libcdio.git/commit/?id=f6f9c48fb40b8a1e8218799724b0b61a7161eb1d | third party advisory patch |
https://access.redhat.com/errata/RHSA-2018:3246 | vendor advisory |