Vulnerability CVE-2020-35492: Information

Description

A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: March 18, 2021
Modified: May 3, 2023
Error type identifier: CWE-787

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libcairosisyphus1.16.0-alt21.18.0-alt1ALT-PU-2022-3396-1312186Fixed
libcairosisyphus_e2k1.16.0-alt21.18.0-alt1ALT-PU-2022-7547-1-Fixed
libcairosisyphus_riscv641.17.8-alt11.18.0-alt1ALT-PU-2023-4618-1-Fixed
libcairop101.16.0-alt21.16.0-alt2ALT-PU-2023-1010-2312192Fixed
libcairop10_e2k1.16.0-alt21.16.0-alt2ALT-PU-2023-2177-1-Fixed
libcairoc10f11.16.0-alt21.16.0-alt2ALT-PU-2023-1010-2312192Fixed
libcairoc9f21.16.0-alt21.16.0-alt2ALT-PU-2023-1002-2312258Fixed
libcairop111.16.0-alt21.18.0-alt1ALT-PU-2022-3396-1312186Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:cairographics:cairo:*:*:*:*:*:*:*:*
      End excliding
      1.17.4