Summary: | x11-libs/cairo: NULL pointer dereference with a crafted font file (CVE-2017-7475) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | normal | CC: | sudormrfhalt, tetromino, x11 |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://gitlab.freedesktop.org/cairo/cairo/-/issues/80 | ||
Whiteboard: | A3 [upstream cve] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() *** Bug 621392 has been marked as a duplicate of this bug. *** Maintainers, please take a look at this. RedHat decided that they are not going to fix this. https://access.redhat.com/security/cve/cve-2017-7475 (In reply to Yury German from comment #2) > Maintainers, please take a look at this. RedHat decided that they are not > going to fix this. > https://access.redhat.com/security/cve/cve-2017-7475 Bug is still open... https://bugzilla.redhat.com/show_bug.cgi?id=1447949 This remains open with no patch: https://gitlab.freedesktop.org/cairo/cairo/issues/80 (In reply to Sam James (sec padawan) from comment #4) > This remains open with no patch: > https://gitlab.freedesktop.org/cairo/cairo/issues/80 There is a proposed patch (https://bugs.freedesktop.org/attachment.cgi?id=131213) but upstream aren't sure about it: https://gitlab.freedesktop.org/cairo/cairo/issues/80#note_51228. So it's more of a stopgap "fix" than anything complete. |