5.5
CVSSv3

CVE-2016-9082

Published: 03/02/2017 Updated: 02/04/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer overflow in the write_png function in cairo 1.14.6 allows remote malicious users to cause a denial of service (invalid pointer dereference) via a large svg file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cairographics cairo 1.14.6

Vendor Advisories

Several security issues were fixed in cairo ...
Debian Bug report logs - #842289 cairo: CVE-2016-9082: Out of bounds read in read_png/write_png in cairo-pngc Package: src:cairo; Maintainer for src:cairo is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 27 Oct 2016 18:18:01 ...
Integer overflow in the write_png function in cairo 1146 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file ...