Description
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.
Published: 2021-03-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2518-1 cairo security update
EUVD EUVD EUVD-2020-23161 A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.
Ubuntu USN Ubuntu USN USN-5407-1 Cairo vulnerabilities
History

No history.

Subscriptions

Cairographics Cairo
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-02-13T16:27:43.741Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2020-35492

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-18T19:15:13.230

Modified: 2024-11-21T05:27:24.803

Link: CVE-2020-35492

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-12-28T00:00:00Z

Links: CVE-2020-35492 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses