Medium severity5.5NVD Advisory· Published May 19, 2017· Updated May 13, 2026
CVE-2017-7475
CVE-2017-7475
Description
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cairoRubyGems | >= 1.15.4, < 1.15.5 | 1.15.5 |
Affected products
2- cpe:2.3:a:cairographics:cairo:1.15.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- bugs.freedesktop.org/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- seclists.org/oss-sec/2017/q2/151nvdMailing ListThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-5v3f-73gv-x7x5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-7475ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/cairo/CVE-2017-7475.ymlghsaWEB
- lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Envd
News mentions
0No linked articles in our index yet.