QID 352279

Date Published: 2021-05-13

QID 352279: Amazon Linux Security Update for cairo: ALAS-2020-1392

<DIV> Issue Overview:

The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a negative span length. (CVE-2016-3190 )

</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 352279

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2020-1392 Amazon Linux URL Logo alas.aws.amazon.com/ALAS-2020-1392.html