Do your applications use this vulnerable package?
Test your applications
Overview
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2017-7475
- CWE
- CWE-476
- Snyk ID
- SNYK-UBUNTU1804-CAIRO-344900
- Disclosed
- 19 May, 2017
- Published
- 19 May, 2017