{"id":"UBUNTU-CVE-2021-42522","details":"There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of 'xmlGetProp()'.","modified":"2026-04-22T13:01:32.335901Z","published":"2022-08-25T18:15:00Z","upstream":["CVE-2021-42522"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-42522"},{"type":"REPORT","url":"https://gitlab.gnome.org/Archive/anjuta/-/issues/12"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/anjuta/-/issues/12"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-42522"}],"affected":[{"package":{"name":"anjuta","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/anjuta@2:3.18.2-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:3.16.0-1","2:3.18.0-1","2:3.18.2-1"],"ecosystem_specific":{"binaries":[{"binary_name":"anjuta","binary_version":"2:3.18.2-1"},{"binary_version":"2:3.18.2-1","binary_name":"anjuta-common"},{"binary_name":"gir1.2-anjuta-3.0","binary_version":"2:3.18.2-1"},{"binary_name":"libanjuta-3-0","binary_version":"2:3.18.2-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-42522.json"}},{"package":{"name":"anjuta","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/anjuta@2:3.28.0-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:3.26.0-1","2:3.26.0-2","2:3.26.0-3","2:3.26.0-4","2:3.26.0-4ubuntu1","2:3.26.0-5","2:3.28.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"anjuta","binary_version":"2:3.28.0-1"},{"binary_version":"2:3.28.0-1","binary_name":"anjuta-common"},{"binary_name":"gir1.2-anjuta-3.0","binary_version":"2:3.28.0-1"},{"binary_name":"libanjuta-3-0","binary_version":"2:3.28.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-42522.json"}},{"package":{"name":"anjuta","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/anjuta@2:3.34.0-3ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:3.34.0-2","2:3.34.0-3","2:3.34.0-3build1","2:3.34.0-3build2","2:3.34.0-3ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"anjuta","binary_version":"2:3.34.0-3ubuntu1"},{"binary_name":"anjuta-common","binary_version":"2:3.34.0-3ubuntu1"},{"binary_name":"gir1.2-anjuta-3.0","binary_version":"2:3.34.0-3ubuntu1"},{"binary_version":"2:3.34.0-3ubuntu1","binary_name":"libanjuta-3-0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-42522.json"}},{"package":{"name":"anjuta","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/anjuta@2:3.34.0-5?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:3.34.0-3ubuntu3","2:3.34.0-4","2:3.34.0-5"],"ecosystem_specific":{"binaries":[{"binary_name":"anjuta","binary_version":"2:3.34.0-5"},{"binary_name":"anjuta-common","binary_version":"2:3.34.0-5"},{"binary_version":"2:3.34.0-5","binary_name":"gir1.2-anjuta-3.0"},{"binary_version":"2:3.34.0-5","binary_name":"libanjuta-3-0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-42522.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}