REDHAT-BUG-2501732: Buffer Overflow
A flaw was found in xdgmime, affecting all versions. A heap-based buffer overflow can occur in xdgmimemagicparsemagicline() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDGDATAHOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via gcontenttypeguess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption. To exploit this flaw, an attacker must trick a user into installing a malicious MIME magic file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2501732?
The severity of REDHAT-BUG-2501732 is medium with a score of 4.
What vulnerability does REDHAT-BUG-2501732 describe?
REDHAT-BUG-2501732 describes a heap-based buffer overflow in the xdgmime component.
How can REDHAT-BUG-2501732 be exploited?
REDHAT-BUG-2501732 can be exploited via an attacker-controlled MIME magic file in a user-writable XDG data location.
What is the affected software in REDHAT-BUG-2501732?
The affected software in REDHAT-BUG-2501732 is xdgmime.
What systems are impacted by REDHAT-BUG-2501732?
REDHAT-BUG-2501732 impacts little-endian systems.