cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and renderrows functions) and cairo-image-compositor.c (the _cairoimagespansand_zero function).
{ "binaries": [ { "binary_version": "1.16.0-5ubuntu2", "binary_name": "cairo-perf-utils" }, { "binary_version": "1.16.0-5ubuntu2", "binary_name": "libcairo-gobject2" }, { "binary_version": "1.16.0-5ubuntu2", "binary_name": "libcairo-script-interpreter2" }, { "binary_version": "1.16.0-5ubuntu2", "binary_name": "libcairo2" }, { "binary_version": "1.16.0-5ubuntu2", "binary_name": "libcairo2-dev" } ] }
{ "binaries": [ { "binary_version": "1.18.0-3build1", "binary_name": "libcairo-gobject2" }, { "binary_version": "1.18.0-3build1", "binary_name": "libcairo-script-interpreter2" }, { "binary_version": "1.18.0-3build1", "binary_name": "libcairo2" }, { "binary_version": "1.18.0-3build1", "binary_name": "libcairo2-dev" } ] }
{ "binaries": [ { "binary_version": "1.18.4-1", "binary_name": "libcairo-gobject2" }, { "binary_version": "1.18.4-1", "binary_name": "libcairo-script-interpreter2" }, { "binary_version": "1.18.4-1", "binary_name": "libcairo2" }, { "binary_version": "1.18.4-1", "binary_name": "libcairo2-dev" } ] }
{ "binaries": [ { "binary_version": "1.14.6-1ubuntu0.1~esm1", "binary_name": "cairo-perf-utils" }, { "binary_version": "1.14.6-1ubuntu0.1~esm1", "binary_name": "libcairo-gobject2" }, { "binary_version": "1.14.6-1ubuntu0.1~esm1", "binary_name": "libcairo-script-interpreter2" }, { "binary_version": "1.14.6-1ubuntu0.1~esm1", "binary_name": "libcairo2" }, { "binary_version": "1.14.6-1ubuntu0.1~esm1", "binary_name": "libcairo2-dev" } ] }
{ "binaries": [ { "binary_version": "1.15.10-2ubuntu0.1", "binary_name": "cairo-perf-utils" }, { "binary_version": "1.15.10-2ubuntu0.1", "binary_name": "libcairo-gobject2" }, { "binary_version": "1.15.10-2ubuntu0.1", "binary_name": "libcairo-script-interpreter2" }, { "binary_version": "1.15.10-2ubuntu0.1", "binary_name": "libcairo2" }, { "binary_version": "1.15.10-2ubuntu0.1", "binary_name": "libcairo2-dev" } ] }
{ "binaries": [ { "binary_version": "1.16.0-4ubuntu1", "binary_name": "cairo-perf-utils" }, { "binary_version": "1.16.0-4ubuntu1", "binary_name": "libcairo-gobject2" }, { "binary_version": "1.16.0-4ubuntu1", "binary_name": "libcairo-script-interpreter2" }, { "binary_version": "1.16.0-4ubuntu1", "binary_name": "libcairo2" }, { "binary_version": "1.16.0-4ubuntu1", "binary_name": "libcairo2-dev" } ] }