Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:1961

Опубликовано: 10 мая 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: cairo and pixman security and bug fix update

Cairo is a 2D graphics library designed to provide high-quality display and print output.

Pixman is a pixel manipulation library for the X Window System and Cairo.

Security Fix(es):

  • cairo: libreoffice slideshow aborts with stack smashing in cairo's composite_boxes (CVE-2020-35492)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
cairox86_646.el8cairo-1.15.12-6.el8.x86_64.rpm
cairo-develx86_646.el8cairo-devel-1.15.12-6.el8.x86_64.rpm
cairo-gobjectx86_646.el8cairo-gobject-1.15.12-6.el8.x86_64.rpm
cairo-gobject-develx86_646.el8cairo-gobject-devel-1.15.12-6.el8.x86_64.rpm
pixmanx86_642.el8pixman-0.38.4-2.el8.x86_64.rpm
pixman-develx86_642.el8pixman-devel-0.38.4-2.el8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
redhat
больше 4 лет назад

A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
nvd
больше 4 лет назад

A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 4 лет назад

A flaw was found in cairo's image-compositor.c in all versions prior t ...