CVE-2020-35492 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A flaw was found in cairo's image-compositor.c. An attacker who is able to provide a crafted input file to cairo's image-compositor (e.g. by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) could cause a stack buffer overflow leading to an out-of-bounds write.
Group Package Affected Fixed Severity Status Ticket
AVG-1392 lib32-cairo 1.17.4-4 1.17.4-5 Medium Fixed FS#70017
AVG-1391 cairo 1.17.4-4 1.17.4-5 Medium Fixed FS#70017
References
https://bugzilla.redhat.com/show_bug.cgi?id=1898396
https://gitlab.freedesktop.org/cairo/cairo/-/issues/437
https://gitlab.freedesktop.org/cairo/cairo/uploads/70783d7cd4183eb250dfd124c1c15e9b/crash.odp
https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/85
https://gitlab.freedesktop.org/cairo/cairo/-/commit/03a820b173ed1fdef6ff14b4468f5dbc02ff59be