CVE-2020-35492 log
| Source |
|
| Severity | Medium |
| Remote | No |
| Type | Arbitrary code execution |
| Description | A flaw was found in cairo's image-compositor.c. An attacker who is able to provide a crafted input file to cairo's image-compositor (e.g. by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) could cause a stack buffer overflow leading to an out-of-bounds write. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1392 | lib32-cairo | 1.17.4-4 | 1.17.4-5 | Medium | Fixed | FS#70017 |
| AVG-1391 | cairo | 1.17.4-4 | 1.17.4-5 | Medium | Fixed | FS#70017 |