CVE-2018-18064

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
08/10/2018
Last modified:
07/11/2023

Description

cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cairographics:cairo:*:*:*:*:*:*:*:* 1.15.14 (including)