First published: Wed Dec 05 2018(Updated: )
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cairo Graphics | =1.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19876 has a medium severity level due to the potential for application crashes.
To fix CVE-2018-19876, upgrade to a patched version of cairo that addresses the memory management issue.
CVE-2018-19876 can lead to application instability and crashes, specifically resulting in a 'free(): invalid pointer' error.
CVE-2018-19876 affects cairo version 1.16.0.
Yes, CVE-2018-19876 is particularly relevant for applications using WebKit, due to the compatibility issue with its memory management.