ALT-PU-2025-14959-2
Closed vulnerabilities
Published: 2022-11-02
Modified: 2025-03-05
Modified: 2025-03-05
BDU:2022-06588
Уязвимость реализации функции malloc() библиотеки shapelib, позволяющая нарушителю вызвать отказ в обслуживании
Severity: CRITICAL (9.8)Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: CRITICAL (10.0)Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
References:
Published: 2022-10-17
Modified: 2026-01-24
Modified: 2026-01-24
CVE-2022-0699
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.
Severity: CRITICAL (9.8)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/OSGeo/shapelib/commit/c75b9281a5b9452d92e1682bdfe6019a13ed819f
- https://github.com/OSGeo/shapelib/issues/39
- https://github.com/OSGeo/shapelib/commit/c75b9281a5b9452d92e1682bdfe6019a13ed819f
- https://github.com/OSGeo/shapelib/issues/39
- https://lists.debian.org/debian-lts-announce/2026/01/msg00023.html
