Bug 889495 (CVE-2014-5116) - VUL-1: CVE-2014-5116: cairo: NULL pointer dereference in cairo_image_surface_get_data()
Summary: VUL-1: CVE-2014-5116: cairo: NULL pointer dereference in cairo_image_surface_...
Status: RESOLVED WONTFIX
Alias: CVE-2014-5116
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Mu Lei
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/104092/
Whiteboard: CVSSv2:NVD:CVE-2014-5116:5.0:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-30 07:10 UTC by Victor Pereira
Modified: 2020-04-01 22:11 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-07-30 07:10:24 UTC
CVE-2014-5116

The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and
Wireshark, allows context-dependent attackers to cause a denial of service (NULL
pointer dereference) via a large string.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1124500
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5116
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9761
http://www.osvdb.org/107083
http://www.exploit-db.com/exploits/33384
Comment 2 Dominique Leuenberger 2014-07-30 07:20:49 UTC
Initial collection of versions used inside openSUSE releases (not conclusive yet which versions are affected).

openSUSE:Factory    => 1.12.16
openSUSE:13.1       => 1.12.16
openSUSE:12.3       => 1.12.8
openSUSE:12.2       => 1.12.2
openSUSE:12.1       => 1.10.2

Hence, if the original statement of '1.10.2' being affected then that would translate to openSUSE:12.1 (EOL).

But, as said: it's not yet known if the vulnerability exists in 1.12.x
Comment 3 Swamp Workflow Management 2014-07-30 22:00:18 UTC
bugbot adjusting priority
Comment 6 Marcus Meissner 2014-09-12 09:52:55 UTC
as its a abort only. and usually the user program should take care, I would close this issue as "not for cairo to fix"