CVE-2014-5116: Null Pointer Dereference
Published Jul 29, 2014
·Updated
The cairoimagesurfacegetdata function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.
Affected Software
1 affected component
Cairographics Cairo=1.10.2
Event History
Jul 29, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5116?
CVE-2014-5116 is classified as a denial of service vulnerability.
2
How do I fix CVE-2014-5116?
To fix CVE-2014-5116, update the Cairo library to a version later than 1.10.2.
3
Which software is affected by CVE-2014-5116?
CVE-2014-5116 affects Cairo 1.10.2, as well as software using this library, like GTK+ and Wireshark.
4
What type of attack does CVE-2014-5116 enable?
CVE-2014-5116 enables a denial of service attack through a NULL pointer dereference.
5
Is CVE-2014-5116 easy to exploit?
The exploitability of CVE-2014-5116 depends on the context and conditions under which it is used.