CVE-2017-9814: High severity cairo graphics vulnerability
Published Jul 14, 2017
·Updated
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
Affected Software
2 affected components
Cairographics Cairo<=1.15.6
openSUSE Leap=15.1
Event History
Jul 14, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9814?
CVE-2017-9814 has a severity rating that indicates a potential denial of service due to out-of-bounds reads.
2
How do I fix CVE-2017-9814?
To fix CVE-2017-9814, users should update to versions later than 1.15.6 of the Cairo graphics library.
3
What software is affected by CVE-2017-9814?
CVE-2017-9814 affects Cairo library versions up to and including 1.15.6 and SUSE Linux Leap 15.1.
4
What type of vulnerability is CVE-2017-9814?
CVE-2017-9814 is categorized as a denial of service vulnerability due to an out-of-bounds read issue.
5
Can CVE-2017-9814 be exploited remotely?
Yes, CVE-2017-9814 can be exploited by remote attackers to cause a denial of service.