ALT-BU-2014-3061-2
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2016-01641
Уязвимость библиотеки векторной графики Cairo, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-04-12
CVE-2014-5116
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.
Modified: 2025-04-12
CVE-2016-3190
The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a negative span length.
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00029.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1318977
- https://cgit.freedesktop.org/cairo/patch/src/cairo-image-compositor.c?id=5c82d91a5e15d29b1489dcb413b24ee7fdf59934
- https://mail.gnome.org/archives/gnome-announce-list/2015-March/msg00047.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00029.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1318977
- https://cgit.freedesktop.org/cairo/patch/src/cairo-image-compositor.c?id=5c82d91a5e15d29b1489dcb413b24ee7fdf59934
- https://mail.gnome.org/archives/gnome-announce-list/2015-March/msg00047.html
Modified: 2025-04-20
CVE-2016-9082
Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.
- http://www.openwall.com/lists/oss-security/2016/10/27/2
- http://www.securityfocus.com/bid/93931
- https://bugs.freedesktop.org/attachment.cgi?id=127421
- https://bugs.freedesktop.org/show_bug.cgi?id=98165
- https://bugzilla.redhat.com/show_bug.cgi?id=1312337
- https://security.gentoo.org/glsa/201904-01
- http://www.openwall.com/lists/oss-security/2016/10/27/2
- http://www.securityfocus.com/bid/93931
- https://bugs.freedesktop.org/attachment.cgi?id=127421
- https://bugs.freedesktop.org/show_bug.cgi?id=98165
- https://bugzilla.redhat.com/show_bug.cgi?id=1312337
- https://security.gentoo.org/glsa/201904-01
Modified: 2025-04-20
CVE-2017-7475
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
- http://seclists.org/oss-sec/2017/q2/151
- https://bugs.freedesktop.org/show_bug.cgi?id=100763
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
- http://seclists.org/oss-sec/2017/q2/151
- https://bugs.freedesktop.org/show_bug.cgi?id=100763
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
Package firefox-TabMixPlus updated to version 0.4.1.5.2-alt1 for branch sisyphus in task 132738.
Closed bugs
Обновить до последней версии