CVE-2020-35492
HIGHcairo < 1.17.4 - Stack-based Buffer Overflow in image-compositor.c
Title source: llmDescription
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.
References (2)
Core 2
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1898396
Third Party Advisory
https://security.gentoo.org/glsa/202305-21
Scores
CVSS v3
7.8
EPSS
0.0111
EPSS Percentile
61.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-121
CWE-787
Status
published
Products (1)
cairographics/cairo
< 1.17.4
Published
Mar 18, 2021
Tracked Since
Feb 18, 2026