yocto ▾
›
master ▾
›
vulnerability
›
CVE-2017-7475
Component Overview
Vulnerability Overview
Name
CVE-2017-7475
Source
NVD (
link
)
Debian (
link
)
Description
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
CWEs
CWE-476
Published Date
May 19, 2017
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://seclists.org/oss-sec/2017/q2/151
Mailing List
https://bugs.freedesktop.org/show_bug.cgi?id=100763
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475
Issue Tracking
http://seclists.org/oss-sec/2017/q2/151
Mailing List
https://bugs.freedesktop.org/show_bug.cgi?id=100763
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475
Issue Tracking
Analysis
#
Affected Component
Analysis
cairo
Patched
Vulnerability Ratings
#
5.5
CVSSv31
4.3
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
cairo
buildroot
2025.02.x
1.18.4
Not Affected
cairo
buildroot
master
1.18.4
Not Affected
cairo
yocto
kirkstone
1.16.0
Patched
cairo
yocto
scarthgap
1.18.0
Patched
Resolved with patches
#
cairo (yocto:kirkstone)
#
Title
Author
Resolve
1
Patch #1
Fan Xin <fan.xin@jp.fujitsu.com>
CVE-2017-7475
cairo (yocto:master)
#
Title
Author
Resolve
1
Cairo: Fix Denial-of-Service Attack due to Logical Problem in
Fan Xin <fan.xin@jp.fujitsu.com>
CVE-2017-7475
cairo (yocto:scarthgap)
#
Title
Author
Resolve
1
Patch #1
Fan Xin <fan.xin@jp.fujitsu.com>
CVE-2017-7475