Cairo: Buffer Overflow Vulnerability — GLSA 202305-21

A buffer overflow vulnerability has been discovered in Cairo which could result in denial of service.

Affected packages

x11-libs/cairo on all architectures
Affected versions < 1.17.6
Unaffected versions >= 1.17.6

Background

Cairo is a 2D vector graphics library with cross-device output support.

Description

An attacker with the ability to provide input to Cairo's image-compositor can cause a buffer overwrite.

Impact

Malicious input to Cairo's image-compositor can result in denial of service of the application using such Cairo functionality.

Workaround

There is no known workaround at this time.

Resolution

All Cairo users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=x11-libs/cairo-1.17.6"
 

References

Release date
May 03, 2023

Latest revision
May 03, 2023: 1

Severity
normal

Exploitable
remote

Bugzilla entries