REDHAT-BUG-1647043: Double Free
An issue was discovered in GNU gettext 0.19.8. There is a double free in defaultaddmessage in read-catalog.c, related to an invalid free in pogramparse in po-gram-gen.y, as demonstrated by lt-msgfmt.
References: https://github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/doublefree https://github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/heapcorruption
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1647043?
The severity of REDHAT-BUG-1647043 is classified as moderate due to the potential for a double free vulnerability.
How do I fix REDHAT-BUG-1647043?
To fix REDHAT-BUG-1647043, update to the latest version of GNU gettext that addresses the double free issue.
What systems are affected by REDHAT-BUG-1647043?
REDHAT-BUG-1647043 affects systems using GNU gettext 0.19.8 and earlier versions.
Is there a known exploit for REDHAT-BUG-1647043?
Yes, there are proofs of concept available that demonstrate the exploitation of the double free vulnerability in GNU gettext 0.19.8.
What should I do if I cannot update GNU gettext to fix REDHAT-BUG-1647043?
If an update is not possible, consider mitigating the risk by restricting access to the affected software or disabling its use until a patch can be applied.