CVE-2017-9814

Published: 17 July 2017

cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.

Priority

Low

CVSS 3 base score: 7.5

Status

Package Release Status
cairo
Launchpad, Ubuntu, Debian
Upstream Needed

Ubuntu 21.04 (Hirsute Hippo) Deferred

Ubuntu 20.10 (Groovy Gorilla) Deferred

Ubuntu 20.04 LTS (Focal Fossa) Deferred

Ubuntu 18.04 LTS (Bionic Beaver) Deferred

Ubuntu 16.04 LTS (Xenial Xerus) Deferred

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was deferred [2020-11-26])
Patches:
Other: https://bugs.freedesktop.org/attachment.cgi?id=132563