CVE Vulnerabilities

CVE-2017-7475

NULL Pointer Dereference

Published: May 19, 2017 | Modified: Feb 12, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
LOW

Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Cairo Cairographics 1.15.4 (including) 1.15.4 (including)
Cairo Ubuntu artful *
Cairo Ubuntu bionic *
Cairo Ubuntu cosmic *
Cairo Ubuntu disco *
Cairo Ubuntu eoan *
Cairo Ubuntu groovy *
Cairo Ubuntu hirsute *
Cairo Ubuntu impish *
Cairo Ubuntu kinetic *
Cairo Ubuntu lunar *
Cairo Ubuntu mantic *
Cairo Ubuntu precise *
Cairo Ubuntu trusty *
Cairo Ubuntu vivid/stable-phone-overlay *
Cairo Ubuntu xenial *
Cairo Ubuntu yakkety *
Cairo Ubuntu zesty *

Potential Mitigations

References