CVE-2016-9082
Summary
| CVE | CVE-2016-9082 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-03 15:59:00 UTC |
| Updated | 2019-04-02 07:29:00 UTC |
| Description | Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Cairo 'cairo-png.c' Integer Overflow Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Cairo: Denial of Service (GLSA 201904-01) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| bugs.freedesktop.org/attachment.cgi |
CONFIRM |
bugs.freedesktop.org |
Issue Tracking |
| 98165 – (CVE-2016-9082) DoS attack based on using SVG to generate invalid pointers from a _cairo_image_surface in write_png |
CONFIRM |
bugs.freedesktop.org |
Issue Tracking |
| Bug 1312337 – CVE-2016-9082 cairo: Out of bounds read in read_png/write_png in cairo-png.c |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking |
| oss-security - Re: librsvg and cairo are causing libpng to write out-of-bounds |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710183 Gentoo Linux Cairo Denial of service Vulnerability (GLSA 201904-01)