A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.1.10"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:rpm:libcomps:*:*:*:*:*:*:*:*"
}