double-free in the add_themes_from_dir method
There is a suspected double-free bug (http://cwe.mitre.org/data/definitions/415.html) with static void add_themes_from_dir(DialogData *data,GFile *dir,gboolean editable)
in dlg-contact-sheet.c
. This method involves two successive calls of g_free(buffer)
(line 354 and 373), and is likely to cause double-free of the buffer.
One possible fix could be directly assigning the buffer to NULL
after the first call of g_free(buffer)
.