PT-2017-17759 · Cairo+3 · Cairo+3

Published

2014-10-20

·

Updated

2023-02-12

·

CVE-2017-7475

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cairo version 1.15.4
Description The issue is related to a NULL pointer dereference in the FT Load Glyph and FT Render Glyph functions, resulting in an application crash.
Recommendations For Cairo version 1.15.4, consider updating to a newer version to mitigate the risk, however at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the FT Load Glyph and FT Render Glyph functions until a patch is available.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2282
ALT-PU-2023-1002
ALT-PU-2023-1010
CVE-2017-7475
ECHO-36D1-DB60-5570
GHSA-5V3F-73GV-X7X5
MGASA-2020-0359
OPENSUSE-SU-2024:10671-1
SUSE-SU-2017:1671-1
SUSE-SU-2018:1453-1

Affected Products

Alt Linux
Cairo
Debian
Suse