Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://launchpad.net/bugs/1884738 | issue tracking third party advisory vendor advisory |
https://ubuntu.com/USN-4519-1 | third party advisory vendor advisory |