CVE-2022-25309: Buffer Overflow
A heap based buffer overflow was found in fribidicaprtltounicode.
References:
https://github.com/fribidi/fribidi/issues/182
Other sources
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidicaprtltounicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial of service.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-25309?
CVE-2022-25309 is a heap-based buffer overflow vulnerability in the Fribidi package.
How does CVE-2022-25309 affect Fribidi?
CVE-2022-25309 affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file.
What is the severity of CVE-2022-25309?
The severity of CVE-2022-25309 is medium with a CVSS score of 5.5.
Which software is affected by CVE-2022-25309?
The GNU FriBidi version up to 1.0.12 and Redhat Enterprise Linux versions 8.0 and 9.0 are affected by CVE-2022-25309.
How can I fix CVE-2022-25309?
Update the affected software to a version that includes a fix for CVE-2022-25309.