A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://github.com/autotrace/autotrace/commits/master | third party advisory patch |
https://github.com/autotrace/autotrace/pull/40 | third party advisory patch |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NC6MUH2RLVEA634LHBNZ2KO7MQKI2RDZ/ | vendor advisory |