Bug 2088224 (CVE-2021-42702) - CVE-2021-42702 inkscape: Inkscape can access an uninitialized pointer that allowes to unauthorized information.
Summary: CVE-2021-42702 inkscape: Inkscape can access an uninitialized pointer that al...
Keywords:
Status: NEW
Alias: CVE-2021-42702
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2096831 2096832 2096833 2096834 2096835 2096836
Blocks: 2088223
TreeView+ depends on / blocked
 
Reported: 2022-05-19 03:55 UTC by Sandipan Roy
Modified: 2023-07-07 08:30 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Inkscape, which is vulnerable to accessing an uninitialized pointer. This flaw allows an attacker to have access to unauthorized information.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2022-05-19 03:55:44 UTC
Inkscape version 0.19 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.

https://www.cisa.gov/uscert/ics/advisories/icsa-22-132-03

Comment 1 Sandipan Roy 2022-06-14 11:58:20 UTC
Created inkscape tracking bugs for this issue:

Affects: fedora-all [bug 2096831]

Comment 3 Jan Horak 2022-08-04 14:17:24 UTC
We have inkscape 0.92 in the RHEL, so since this affects 0.91 I don't think we are affected, or do you think otherwise?


Note You need to log in before you can comment on or make changes to this bug.