CVE-2018-19876
Summary
| CVE | CVE-2018-19876 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-05 20:29:00 UTC |
| Updated | 2019-01-31 19:27:00 UTC |
| Description | cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ft: Use FT_Done_MM_Var instead of free when available in cairo_ft_apply_variations (!5) · Merge Requests · cairo / cairo · GitLab |
MISC |
gitlab.freedesktop.org |
Patch, Third Party Advisory |
| 191595 – [FreeType] Problem under WebCore::FontPlatformData::FontPlatformData |
MISC |
bugs.webkit.org |
Issue Tracking, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500087 Alpine Linux Security Update for cairo
- 503760 Alpine Linux Security Update for cairo
- 900196 CBL-Mariner Linux Security Update for cairo 1.16.0
- 903695 Common Base Linux Mariner (CBL-Mariner) Security Update for cairo (1980)