CVE-2018-18064: Medium severity cairo graphics vulnerability
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and renderrows functions) and cairo-image-compositor.c (the cairoimagespansandzero function).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18064?
CVE-2018-18064 has a high severity due to the potential for out-of-bounds stack-memory writes, which could lead to exploitation.
How do I fix CVE-2018-18064?
To fix CVE-2018-18064, upgrade cairo to version 1.15.15 or later, which addresses this vulnerability.
What software is affected by CVE-2018-18064?
CVE-2018-18064 affects cairo graphics versions up to and including 1.15.14.
What type of attack does CVE-2018-18064 enable?
CVE-2018-18064 enables potential remote code execution attacks due to the out-of-bounds memory writes.
How can I determine if my software is vulnerable to CVE-2018-18064?
You can determine if your software is vulnerable to CVE-2018-18064 by checking the version of cairo installed and comparing it to version 1.15.14.