Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2023.5922.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-5922-1)
Summary:The remote host is missing an update for the 'fribidi' package(s) announced via the USN-5922-1 advisory.
Description:Summary:
The remote host is missing an update for the 'fribidi' package(s) announced via the USN-5922-1 advisory.

Vulnerability Insight:
It was discovered that FriBidi incorrectly handled the processing of input
strings, resulting in memory corruption. An attacker could possibly use this
issue to cause FriBidi to crash, resulting in a denial of service, or
potentially execute arbitrary code. (CVE-2022-25308)

It was discovered that FriBidi incorrectly validated input data to its CapRTL
unicode encoder, resulting in memory corruption. An attacker could possibly
use this issue to cause FriBidi to crash, resulting in a denial of service, or
potentially execute arbitrary code. (CVE-2022-25309)

It was discovered that FriBidi incorrectly handled empty input when removing
marks from unicode strings. An attacker could possibly use this to cause
FriBidi to crash, resulting in a denial of service, or potentially execute
arbitrary code. (CVE-2022-25310)

Affected Software/OS:
'fribidi' package(s) on Ubuntu 16.04.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-25308
https://access.redhat.com/security/cve/CVE-2022-25308
https://bugzilla.redhat.com/show_bug.cgi?id=2047890
https://github.com/fribidi/fribidi/issues/181
https://github.com/fribidi/fribidi/pull/184
Common Vulnerability Exposure (CVE) ID: CVE-2022-25309
https://access.redhat.com/security/cve/CVE-2022-25309
https://bugzilla.redhat.com/show_bug.cgi?id=2047896
https://github.com/fribidi/fribidi/commit/f22593b82b5d1668d1997dbccd10a9c31ffea3b3
https://github.com/fribidi/fribidi/issues/182
Common Vulnerability Exposure (CVE) ID: CVE-2022-25310
https://access.redhat.com/security/cve/CVE-2022-25310
https://bugzilla.redhat.com/show_bug.cgi?id=2047923
https://github.com/fribidi/fribidi/issues/183
https://github.com/fribidi/fribidi/pull/186
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.