JLSEC-2025-17
Dashboard / Vulnerabilities / JLSEC-2025-17
Summary: A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4
Details: A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.
References: https://bugzilla.redhat.com/show_bug.cgi?id=1898396, https://security.gentoo.org/glsa/202305-21
Affected packages
Package
Name: Cairo_jll
Purl: pkg:julia/Cairo_jll?uuid=83423d85-b0ee-5818-9007-b63ccbeb887a
Affected ranges
Type: SEMVER
Events:
