Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-6462

Опубликовано: 11 янв. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

A vulnerability was found in Cairo due to an infinite loop in the _arc_error_normalized function within cairo-arc.c, where an attacker can exploit this flaw by convincing a victim to open a specially crafted file, causing the application to enter an infinite loop and resulting in a denial of service.

Отчет

This vulnerability is rated as a moderate because it allows a denial of service due to an infinite loop in the _arc_error_normalized function within cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized, exploiting this issue requires processing specific input, which can cause applications to become unresponsive and the impact is limited to availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cairoWill not fix
Red Hat Enterprise Linux 6cairoWill not fix
Red Hat Enterprise Linux 6chromium-browserNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7cairoWill not fix
Red Hat Enterprise Linux 8cairoWill not fix
Red Hat Enterprise Linux 8mingw-cairoWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1671399cairo: infinite loop in the function _arc_error_normalized in the file cairo-arc.c

EPSS

Процентиль: 80%
0.02142
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

CVSS3: 6.5
nvd
больше 7 лет назад

An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

CVSS3: 6.5
msrc
почти 6 лет назад

Описание отсутствует

CVSS3: 6.5
debian
больше 7 лет назад

An issue was discovered in cairo 1.16.0. There is an infinite loop in ...

suse-cvrf
около 2 лет назад

Security update for cairo

EPSS

Процентиль: 80%
0.02142
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2019-6462