CVE-2019-6245
Summary
| CVE | CVE-2019-6245 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-13 00:29:00 UTC |
| Updated | 2023-04-01 18:15:00 UTC |
| Description | An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call itself recursively. There can be a situation where (x2 - x1) is always bigger than dx_limit during the recursion, leading to continual stack consumption. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2872-1] agg security update |
MLIST |
lists.debian.org |
|
| 4 bugs found in svgpp · Issue #70 · svgpp/svgpp · GitHub |
MISC |
github.com |
Exploit, Patch, Third Party Advisory |
| [SECURITY] [DLA 1656-1] agg security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 3376-1] svgpp security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178982 Debian Security Update for agg (DLA 2872-1)
- 181652 Debian Security Update for svgpp (DLA 3376-1)