Stack-based buffer overflow in Cairo - CVE-2020-35492

 

Stack-based buffer overflow in Cairo - CVE-2020-35492

Published: March 18, 2021 / Updated: April 13, 2021


Vulnerability identifier: #VU52196
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35492
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.


Affected software

Cairo
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
openEuler
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
cairo (Alpine package)
pixman-devel
pixman
pixman (Red Hat package)
cairo (Ubuntu package)
cairo-perf-utils (Ubuntu package)
libcairo2 (Ubuntu package)
cairo-gobject-devel
cairo-gobject
cairo-devel
cairo
cairo (Red Hat package)
cairo-debugsource
cairo-debuginfo
x11-libs/cairo
IBM Watson Machine Learning Accelerator
OpenShift Virtualization

How to mitigate CVE-2020-35492

Install update from vendor's website.

Migration Toolkit for Containers - addressed in versions 1.6.5, 1.7.2
cairo (Alpine package) - update to 1.16.0-r3
IBM Watson Machine Learning Accelerator - update to 5.0.3
pixman-devel - update to 0.38.4-2
pixman - update to 0.38.4-2
pixman (Red Hat package) - update to 0.38.4-2.el8
cairo (Ubuntu package) - addressed in versions 1.14.6-1ubuntu0.1~esm2, 1.15.10-2ubuntu0.1+esm1, 1.16.0-4ubuntu1+esm1, 1.16.0-5ubuntu2.1
cairo-perf-utils (Ubuntu package) - update to 1.14.61ubuntu0.1~esm1
libcairo2 (Ubuntu package) - update to 1.14.61ubuntu0.1~esm1
cairo-gobject-devel - update to 1.15.12-6
cairo-gobject - update to 1.15.12-6
cairo-devel - update to 1.15.12-6
cairo - update to 1.15.12-6
cairo (Red Hat package) - update to 1.15.12-6.el8
cairo-devel - update to 1.16.0-3
cairo-debugsource - update to 1.16.0-3
cairo-debuginfo - update to 1.16.0-3
cairo - update to 1.16.0-3
x11-libs/cairo - update to 1.17.6
OpenShift Virtualization - update to 4.11.0
Red Hat OpenShift Container Platform - update to 4.11.0

External References

Related Security Bulletins