Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A flaw was found in xdgmime, affecting all versions. A heap-based buffer overflow can occur in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption. To exploit this flaw, an attacker must trick a user into installing a malicious MIME magic file.
This was fixed upstream with release 2.89.4. Fedora currently ships 2.89.3 or older across all versions, which means all are affected. That said, the CVE is considered low impact in practice. For Fedora 44 and 45 we can wait for the fix to land on the next upstream stable release. As for Fedora 43, it will be EOL on December 9, so no fix is planned.