Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2017-9814

Published: 17 July 2017

cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.

Notes

AuthorNote
mdeslaur
as of 2020-11-26, no complete fix from upstream
rodrigo-zaiden
upstream closed the issue on Jul/2021 with a merge
containing two other commits to complete the fix.

Priority

Low

CVSS 3 base score: 7.5

Status

Package Release Status
cairo
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic Needs triage

cosmic Ignored
(reached end-of-life)
disco Ignored
(reached end-of-life)
eoan Ignored
(reached end-of-life)
focal Needs triage

groovy Ignored
(reached end-of-life)
hirsute Ignored
(reached end-of-life)
impish Ignored
(reached end-of-life)
jammy Needs triage

kinetic Needs triage

precise Does not exist

trusty Does not exist
(trusty was deferred [2020-11-26])
upstream
Released (1.17.6)
xenial
Released (1.14.6-1ubuntu0.1~esm1)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)
Patches:
other: https://bugs.freedesktop.org/attachment.cgi?id=132563
upstream: https://gitlab.freedesktop.org/cairo/cairo/-/commit/199823938780c8e50099b627d3e9137acba7a263
upstream: https://gitlab.freedesktop.org/cairo/cairo/-/commit/ae04679a08f39597907c28c317062b1f22ecf8f8
upstream: https://gitlab.freedesktop.org/cairo/cairo/-/commit/c91ae5c5a06d1b0f558f9a83637ba5df99cd2af5