There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'errmsg' of 'sqlite3exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.4.4"
},
{
"last_affected": "1.4.5"
}
],
"cpe": [
"cpe:2.3:a:colord_project:colord:1.4.4:*:*:*:*:*:*:*",
"cpe:2.3:a:colord_project:colord:1.4.5:*:*:*:*:*:*:*"
]
}