An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the addthemesfromdir method in dlg-contact-sheet.c because of two successive calls of gfree, each of which frees the same buffer.
{
"binaries": [
{
"binary_version": "3:3.4.3-1ubuntu0.1~esm1",
"binary_name": "gthumb"
},
{
"binary_version": "3:3.4.3-1ubuntu0.1~esm1",
"binary_name": "gthumb-data"
},
{
"binary_version": "3:3.4.3-1ubuntu0.1~esm1",
"binary_name": "gthumb-dev"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "3:3.6.1-1ubuntu0.1~esm1",
"binary_name": "gthumb"
},
{
"binary_version": "3:3.6.1-1ubuntu0.1~esm1",
"binary_name": "gthumb-data"
},
{
"binary_version": "3:3.6.1-1ubuntu0.1~esm1",
"binary_name": "gthumb-dev"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}