CVE-2020-35492 - log back

CVE-2020-35492 edited at 29 Dec 2020 11:43:19
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ A flaw was found in cairo's image-compositor.c. An attacker who is able to provide a crafted input file to cairo's image-compositor (e.g. by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) could cause a stack buffer overflow leading to an out-of-bounds write.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1898396
+ https://gitlab.freedesktop.org/cairo/cairo/-/issues/437
+ https://gitlab.freedesktop.org/cairo/cairo/uploads/70783d7cd4183eb250dfd124c1c15e9b/crash.odp
+ https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/85
+ https://gitlab.freedesktop.org/cairo/cairo/-/commit/03a820b173ed1fdef6ff14b4468f5dbc02ff59be
Notes
CVE-2020-35492 created at 29 Dec 2020 11:40:47