There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'errmsg' of 'sqlite3exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.4.6-1", "binary_name": "colord" }, { "binary_version": "1.4.6-1", "binary_name": "colord-data" }, { "binary_version": "1.4.6-1", "binary_name": "colord-dbgsym" }, { "binary_version": "1.4.6-1", "binary_name": "colord-tests" }, { "binary_version": "1.4.6-1", "binary_name": "colord-tests-dbgsym" }, { "binary_version": "1.4.6-1", "binary_name": "gir1.2-colord-1.0" }, { "binary_version": "1.4.6-1", "binary_name": "gir1.2-colorhug-1.0" }, { "binary_version": "1.4.6-1", "binary_name": "libcolord-dev" }, { "binary_version": "1.4.6-1", "binary_name": "libcolord2" }, { "binary_version": "1.4.6-1", "binary_name": "libcolord2-dbgsym" }, { "binary_version": "1.4.6-1", "binary_name": "libcolorhug-dev" }, { "binary_version": "1.4.6-1", "binary_name": "libcolorhug2" }, { "binary_version": "1.4.6-1", "binary_name": "libcolorhug2-dbgsym" } ] }