UBUNTU-CVE-2019-6247
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-6247
Summary:
Details: An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflow bug in svgpp_agg_render may lead to code execution. In the render_scanlines_aa_solid function, the blend_hline function is called repeatedly multiple times. blend_hline is equivalent to a loop containing write operations. Each call writes a piece of heap data, and multiple calls overwrite the data in the heap.
References: https://ubuntu.com/security/CVE-2019-6247, https://github.com/svgpp/svgpp/issues/70, https://www.cve.org/CVERecord?id=CVE-2019-6247
Affected packages
Package
Name: svgpp
Purl: pkg:deb/ubuntu/[email protected]+dfsg1-3ubuntu1+esm1?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
