A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document.
References
Link | Resource |
---|---|
https://carteryagemann.com/halibut-case-study.html#poc-halibut-info-uaf | Exploit Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CC7UZ7NRXDA7YSCSGWE2CBQM7OZS3K2R/ | Mailing List Third Party Advisory |
Information
Published : 2022-05-24 12:15
Updated : 2022-11-04 09:45
NVD link : CVE-2021-42614
Mitre link : CVE-2021-42614
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
halibut_project
- halibut
fedoraproject
- fedora