First published: Fri Jul 14 2017(Updated: )
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cairo Graphics | <=1.15.6 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9814 has a severity rating that indicates a potential denial of service due to out-of-bounds reads.
To fix CVE-2017-9814, users should update to versions later than 1.15.6 of the Cairo graphics library.
CVE-2017-9814 affects Cairo library versions up to and including 1.15.6 and SUSE Linux Leap 15.1.
CVE-2017-9814 is categorized as a denial of service vulnerability due to an out-of-bounds read issue.
Yes, CVE-2017-9814 can be exploited by remote attackers to cause a denial of service.