A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://carteryagemann.com/halibut-case-study.html#poc-halibut-winhelp-df | third party advisory exploit |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CC7UZ7NRXDA7YSCSGWE2CBQM7OZS3K2R/ | vendor advisory |