CVE-2019-6462

Description

An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.051

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) cairo-debugsource-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo-gobject2-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo-gobject2-32bit-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo-gobject2-debuginfo-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo-gobject2-debuginfo-32bit-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo-script-interpreter2-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo-script-interpreter2-debuginfo-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo2-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo2-32bit-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo2-debuginfo-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2021:3502-1(SUSE Linux Enterprise Server 12-SP5 ) libcairo2-debuginfo-32bit-1.15.2-25.6.2.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) libcairo2-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) cairo-devel-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Desktop Applications Module 15-SP5) libcairo2-32bit-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) cairo-debugsource-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) libcairo-gobject2-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) libcairo2-debuginfo-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Desktop Applications Module 15-SP5) libcairo2-32bit-debuginfo-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) libcairo-gobject2-debuginfo-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) libcairo-script-interpreter2-1.16.0-150400.11.3.1.x86_64.rpmLinux
SUSE-SU-2024:1704-1(Basesystem Module 15-SP5) libcairo-script-interpreter2-debuginfo-1.16.0-150400.11.3.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234