[ubuntu/jammy-security] cairo 1.16.0-5ubuntu2.1 (Accepted)

Ian Constantin ian.constantin at canonical.com
Wed Apr 1 13:55:42 UTC 2026


cairo (1.16.0-5ubuntu2.1) jammy-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow
    - debian/patches/CVE-2017-9814-1.patch: replace calls to malloc with
      _cairo_malloc.
    - debian/patches/CVE-2017-9814-2.patch: check cmap size before allocating
      memory in src/cairo-truetype-subset.c.
    - CVE-2017-9814
  * SECURITY UPDATE: assertion failure
    - debian/patches/CVE-2019-6461.patch: adds check for NaN angles in
      src/cairo-arc.c.
    - CVE-2019-6461
  * SECURITY UPDATE: infinite loop
    - debian/patches/CVE-2019-6462.patch: defines max_segments for use in a
      while loop conditional to prevent an infinite loop in src/cairo-arc.c.
    - CVE-2019-6462

Date: 2026-03-30 13:24:11.344107+00:00
Changed-By: Ian Constantin <ian.constantin at canonical.com>
https://launchpad.net/ubuntu/+source/cairo/1.16.0-5ubuntu2.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list