First published: Mon Oct 08 2018(Updated: )
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cairo Graphics | <=1.15.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18064 has a high severity due to the potential for out-of-bounds stack-memory writes, which could lead to exploitation.
To fix CVE-2018-18064, upgrade cairo to version 1.15.15 or later, which addresses this vulnerability.
CVE-2018-18064 affects cairo graphics versions up to and including 1.15.14.
CVE-2018-18064 enables potential remote code execution attacks due to the out-of-bounds memory writes.
You can determine if your software is vulnerable to CVE-2018-18064 by checking the version of cairo installed and comparing it to version 1.15.14.