CVE-2017-7475: Null Pointer Dereference
Published May 19, 2017
·Updated
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FTLoadGlyph and FTRenderGlyph resulting in an application crash.
Other sources
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FTLoadGlyph and FTRenderGlyph resulting in an application crash.
Affected Software
2 affected componentsFixes available
rubygems/cairo=1.15.4
1.15.5
Cairographics Cairo=1.15.4
Remediation
Patch Available
Event History
May 19, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Nov 15, 2017
Advisory Published
08:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-7475?
CVE-2017-7475 has a severity rating that warrants immediate attention due to its potential to cause application crashes.
2
How do I fix CVE-2017-7475?
To fix CVE-2017-7475, upgrade Cairo to version 1.15.5 or later.
3
Which versions of Cairo are affected by CVE-2017-7475?
Cairo version 1.15.4 is the only affected version regarding CVE-2017-7475.
4
What is the impact of CVE-2017-7475?
The impact of CVE-2017-7475 is a NULL pointer dereference that leads to application crashes.
5
Are there any workarounds for CVE-2017-7475?
There are no recommended workarounds for CVE-2017-7475 other than upgrading to a fixed version.