cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).
References
Link | Resource |
---|---|
https://gitlab.freedesktop.org/cairo/cairo/issues/341 | Exploit Third Party Advisory |
https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E | Mailing List Third Party Advisory |
Configurations
Information
Published : 2018-10-08 11:29
Updated : 2021-03-15 15:28
NVD link : CVE-2018-18064
Mitre link : CVE-2018-18064
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
cairographics
- cairo