First published: Mon Nov 16 2020(Updated: )
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cairo Graphics | <1.17.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35492 has been classified as a high severity vulnerability due to its potential to enable arbitrary code execution through crafted input files.
To fix CVE-2020-35492, update cairo to version 1.17.4 or later to mitigate the vulnerability.
CVE-2020-35492 is a memory corruption vulnerability that can result from improper handling of crafted image files.
CVE-2020-35492 affects all versions of cairo prior to 1.17.4 used in applications that process images.
Yes, CVE-2020-35492 can be exploited remotely if an attacker convinces a user to open a malicious image file.