Do your applications use this vulnerable package?
Test your applications
Overview
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).
References
CVSS Score
6.5
low severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2018-18064
- CWE
- CWE-119
- Snyk ID
- SNYK-DEBIAN9-CAIRO-344861
- Disclosed
- 08 Oct, 2018
- Published
- 08 Oct, 2018