CVE-2016-3190: Buffer Overflow
A vulnerability was found in cairo. A maliciously crafted file can cause out of bounds read in fillxrgb32lerpopaquespans function in cairo, thus crashing the software.
Upstream fix:
https://cgit.freedesktop.org/cairo/patch/src/cairo-image-compositor.c?id=5c82d91a5e15d29b1489dcb413b24ee7fdf59934
References:
http://seclists.org/oss-sec/2016/q1/675
External references:
https://mail.gnome.org/archives/gnome-announce-list/2015-March/msg00047.html
Other sources
The fillxrgb32lerpopaquespans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a negative span length.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3190?
CVE-2016-3190 has been classified as a high severity vulnerability due to its potential to cause crashes in processes utilizing the affected libraries.
How do I fix CVE-2016-3190?
To fix CVE-2016-3190, you should upgrade Cairo to version 1.14.2 or later in your system.
What software is affected by CVE-2016-3190?
CVE-2016-3190 affects Cairo versions up to and including 1.12.16 and is found in packages like cairo for Red Hat and openSUSE 13.2.
What kind of attack does CVE-2016-3190 facilitate?
CVE-2016-3190 can be exploited via a maliciously crafted file that triggers an out of bounds read, potentially leading to application crashes.
Is there a known exploit for CVE-2016-3190?
As of now, there have been no publicly disclosed exploits specifically targeting CVE-2016-3190.