Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Multiple vulnerabilities have been discovered in Cairo, the worst of which a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202408-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Cairo: Multiple Vulnerabilities Date: August 07, 2024 Bugs: #717778 ID: 202408-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Cairo, the worst of which a denial of service. Background ========== Cairo is a 2D vector graphics library with cross-device output support. Affected packages ================= Package Vulnerable Unaffected -------------- ------------ ------------ x11-libs/cairo < 1.18.0 > = 1.18.0 Description =========== Multiple vulnerabilities have been discovered in Cairo. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Cairo users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-libs/cairo-1.18.0" References ========== [ 1 ] CVE-2019-6461 https://nvd.nist.gov/vuln/detail/CVE-2019-6461 [ 2 ] CVE-2019-6462 https://nvd.nist.gov/vuln/detail/CVE-2019-6462 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202408-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
* bsc#1122321 Cross-References: * CVE-2019-6462 . # Security update for cairo Announcement ID: SUSE-SU-2024:1704-2 Rating: low References: * bsc#1122321 Cross-References: * CVE-2019-6462 CVSS scores: * CVE-2019-6462 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2019-6462 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-6462 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for cairo fixes the following issues: * CVE-2019-6462: Fixed a potentially infinite loop (bsc#1122321). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1704=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libcairo2-1.16.0-150400.11.3.1 * libcairo-gobject2-1.16.0-150400.11.3.1 * libcairo-gobject2-debuginfo-1.16.0-150400.11.3.1 * cairo-debugsource-1.16.0-150400.11.3.1 * libcairo2-debuginfo-1.16.0-150400.11.3.1 ## References: * https://www.suse.com/security/cve/CVE-2019-6462.html * https://bugzilla.suse.com/show_bug.cgi?id=1122321 . Cairo security notice issued for SUSE Linux Enterprise Micro 5.5 regarding CVE-2019-6462, categorized as low risk.. SUSE Linux Micro, cairo security update, CVE-2019-6462, security patch, SUSE advisory. . Severity: Low. LinuxSecurity.com Team
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call. (CVE-2017-9814) References: . MGASA-2022-0186 - Updated cairo packages fix security vulnerability Publication date: 15 May 2022 URL: https://advisories.mageia.org/MGASA-2022-0186.html Type: security Affected Mageia releases: 8 CVE: CVE-2017-9814 cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackersto cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call. (CVE-2017-9814) References: - https://bugs.mageia.org/show_bug.cgi?id=30412 - https://ubuntu.com/security/notices/USN-5407-1 - https://www.cve.org/CVERecord?id=CVE-2017-9814 SRPMS: - 8/core/cairo-1.16.0-6.2.mga8 . Cairo security patch resolves a significant denial of service flaw in Mageia 8. Comprehensive information about the resolution provided.. Cairo Security Update,Mageia Advisory,DoS Fix,Security Vulnerability Patch. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in cairo.. =========================================================================Ubuntu Security Notice USN-5407-1 May 10, 2022 cairo vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in cairo. Software Description: - cairo: Cairo 2D vector graphics library performance utilities Details: Gustavo Grieco, Alberto Garcia, Francisco Oca, Suleman Ali, and others discovered that Cairo incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2016-9082, CVE-2017-9814, CVE-2019-6462) Stephan Bergmann discovered that Cairo incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2020-35492) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: cairo-perf-utils 1.14.6-1ubuntu0.1~esm1 libcairo2 1.14.6-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5407-1 CVE-2016-9082, CVE-2017-9814, CVE-2019-6462, CVE-2020-35492 . Remain updated regarding Ubuntu USN-5407-1 which tackles vulnerabilities in cairo, providing guidance for improved security measures.. Cairo Security Issues, Ubuntu Security Update, Denial Of Service, Software Vulnerability, Execution Risk. . Severity: Critical. LinuxSecurity.com Team
An update for cairo and pixman is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: cairo and pixman security and bug fix update Advisory ID: RHSA-2022:1961-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:1961 Issue date: 2022-05-10 CVE Names: CVE-2020-35492 ==================================================================== 1. Summary: An update for cairo and pixman is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Cairo is a 2D graphics library designed to provide high-quality display and print output. Pixman is a pixel manipulation library for the X Window System and Cairo. Security Fix(es): * cairo: libreoffice slideshow aborts with stack smashing in cairo's composite_boxes (CVE-2020-35492) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1898396 - CVE-2020-35492 cairo: libreoffice slideshow aborts with stack smashing in cairo's composite_boxes 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: cairo-1.15.12-6.el8.src.rpm pixman-0.38.4-2.el8.src.rpm aarch64: cairo-1.15.12-6.el8.aarch64.rpm cairo-debuginfo-1.15.12-6.el8.aarch64.rpm cairo-debugsource-1.15.12-6.el8.aarch64.rpm cairo-devel-1.15.12-6.el8.aarch64.rpm cairo-gobject-1.15.12-6.el8.aarch64.rpm cairo-gobject-debuginfo-1.15.12-6.el8.aarch64.rpm cairo-gobject-devel-1.15.12-6.el8.aarch64.rpm cairo-tools-debuginfo-1.15.12-6.el8.aarch64.rpm pixman-0.38.4-2.el8.aarch64.rpm pixman-debuginfo-0.38.4-2.el8.aarch64.rpm pixman-debugsource-0.38.4-2.el8.aarch64.rpm pixman-devel-0.38.4-2.el8.aarch64.rpm ppc64le: cairo-1.15.12-6.el8.ppc64le.rpm cairo-debuginfo-1.15.12-6.el8.ppc64le.rpm cairo-debugsource-1.15.12-6.el8.ppc64le.rpm cairo-devel-1.15.12-6.el8.ppc64le.rpm cairo-gobject-1.15.12-6.el8.ppc64le.rpm cairo-gobject-debuginfo-1.15.12-6.el8.ppc64le.rpm cairo-gobject-devel-1.15.12-6.el8.ppc64le.rpm cairo-tools-debuginfo-1.15.12-6.el8.ppc64le.rpm pixman-0.38.4-2.el8.ppc64le.rpm pixman-debuginfo-0.38.4-2.el8.ppc64le.rpm pixman-debugsource-0.38.4-2.el8.ppc64le.rpm pixman-devel-0.38.4-2.el8.ppc64le.rpm s390x: cairo-1.15.12-6.el8.s390x.rpm cairo-debuginfo-1.15.12-6.el8.s390x.rpm cairo-debugsource-1.15.12-6.el8.s390x.rpm cairo-devel-1.15.12-6.el8.s390x.rpm cairo-gobject-1.15.12-6.el8.s390x.rpm cairo-gobject-debuginfo-1.15.12-6.el8.s390x.rpm cairo-gobject-devel-1.15.12-6.el8.s390x.rpm cairo-tools-debuginfo-1.15.12-6.el8.s390x.rpm pixman-0.38.4-2.el8.s390x.rpm pixman-debuginfo-0.38.4-2.el8.s390x.rpm pixman-debugsource-0.38.4-2.el8.s390x.rpm pixman-devel-0.38.4-2.el8.s390x.rpm x86_64: cairo-1.15.12-6.el8.i686.rpm cairo-1.15.12-6.el8.x86_64.rpm cairo-debuginfo-1.15.12-6.el8.i686.rpm cairo-debuginfo-1.15.12-6.el8.x86_64.rpm cairo-debugsource-1.15.12-6.el8.i686.rpm cairo-debugsource-1.15.12-6.el8.x86_64.rpm cairo-devel-1.15.12-6.el8.i686.rpm cairo-devel-1.15.12-6.el8.x86_64.rpm cairo-gobject-1.15.12-6.el8.i686.rpm cairo-gobject-1.15.12-6.el8.x86_64.rpm cairo-gobject-debuginfo-1.15.12-6.el8.i686.rpm cairo-gobject-debuginfo-1.15.12-6.el8.x86_64.rpm cairo-gobject-devel-1.15.12-6.el8.i686.rpm cairo-gobject-devel-1.15.12-6.el8.x86_64.rpm cairo-tools-debuginfo-1.15.12-6.el8.i686.rpm cairo-tools-debuginfo-1.15.12-6.el8.x86_64.rpm pixman-0.38.4-2.el8.i686.rpm pixman-0.38.4-2.el8.x86_64.rpm pixman-debuginfo-0.38.4-2.el8.i686.rpm pixman-debuginfo-0.38.4-2.el8.x86_64.rpm pixman-debugsource-0.38.4-2.el8.i686.rpm pixman-debugsource-0.38.4-2.el8.x86_64.rpm pixman-devel-0.38.4-2.el8.i686.rpm pixman-devel-0.38.4-2.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-35492 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.6_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYnqRl9zjgjWX9erEAQiU+xAAlV8fTTU5zLgHcTuHoS/FN7ztcJm+mGU6 hGpbZ3R9sIXDXHMSap+9BAJKMT5Mv2L6F5SwYiXdAUMMfDmWT2HOWzRxuER++cRh xr0ST/ihwVfwFCiabrluxIwDj4B9LDqVaPs2Q0AJdI4d8fYevXJYxA9KInJ8xO89 5uvb9Ym6DroKlZ1FVMiB/WaEw/2eiIAGZobmBSWB9uYJE5MkwSISfVSrMuLlqRc0 /u5itFqfGYD5svD8MyIJOYEf3F02ew9VTjGGrmhgmaDPz4uFV26CtWblGcHyElrM vDK8BVS3g+V45+URYnGpnQ1drEOKysxloYO/Y1h0HD0jRrlgzRWMt2Eg2OL/26CW Lm2eIYxyx79AuusTHwIeqQOIAvPpl0MXaIOfJ9vek9x0fM3Mjr+oGE7tpoSLoXGj LsOWlWc7XHNQ/XnTP7Hsp07X3lWgrTwenR+h8s3Ppl/PMluiLuQkt99XsBMBjPr0 aASNDgY509/6cocChAUaasyceYwCMmW4V6neXz3Yr2GKBpyjKn4yJCZo4YO3rx9r g8rS+/DXs4iGEValie/kwcpG3/5lwxW5vgyUB2gpcKD2WWu40iHg5St0nmPl6wZG v2fj6FdodZujJuEHZR9wymcDzhpbSV86HeMaVEDfH+5VLL/6RTAOKlDXQlnJwiEF 8kuVQBwDQJ0=V+q/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized. (CVE-2019-6462) References: . MGASA-2021-0497 - Updated cairo packages fix security vulnerability Publication date: 29 Oct 2021 URL: https://advisories.mageia.org/MGASA-2021-0497.html Type: security Affected Mageia releases: 8 CVE: CVE-2019-6462 An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized. (CVE-2019-6462) References: - https://bugs.mageia.org/show_bug.cgi?id=29582 - https://lists.suse.com/pipermail/sle-security-updates/2021-October/009644.html - https://www.cve.org/CVERecord?id=CVE-2019-6462 SRPMS: - 8/core/cairo-1.16.0-6.1.mga8 . Important notice regarding Mageia security enhancements fixing cairo vulnerabilities. Ensure your system's safety!. Mageia Cairo Update, Cairo Software Fix, Cairo Critical Advisory. . Severity: Critical. LinuxSecurity.com Team
LibreOffice slideshow aborts with stack smashing in cairo’s composite_boxes (CVE-2020-35492). References: - https://bugs.mageia.org/show_bug.cgi?id=28084 . MGASA-2021-0028 - Updated cairo packages fix a security vulnerability Publication date: 14 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0028.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-35492 LibreOffice slideshow aborts with stack smashing in cairo’s composite_boxes (CVE-2020-35492). References: - https://bugs.mageia.org/show_bug.cgi?id=28084 - https://lists.debian.org/debian-lts-announce/2021/01/msg00006.html - https://www.cve.org/CVERecord?id=CVE-2020-35492 SRPMS: - 7/core/cairo-1.16.0-2.2.mga7 . Recent cairo updates in Mageia 7 address a significant security flaw that was leading to abrupt terminations of LibreOffice presentations. Discover more!. Cairo Security, Mageia Advisory, LibreOffice Issue, Cairo Update, Stack Smashing. . Severity: Critical. LinuxSecurity.com Team
LibreOffice slideshow aborts with stack smashing in cairo’s composite_boxes. For Debian 9 stretch, this problem has been fixed in version . - -----------------------------------------------------------------------Debian LTS Advisory DLA-2518-1
Get the latest Linux and open source security news straight to your inbox.