oss-sec mailing list archives

Re: librsvg and cairo are causing libpng to write out-of-bounds


From: Glenn Randers-Pehrson <glennrp () gmail com>
Date: Thu, 6 Oct 2016 15:34:03 -0400

I'm seeing pretty much the same thing on my Ubuntu-16:04 platform,
except that it's using libpng12 instead of libpng16.

On Wed, Oct 5, 2016 at 9:43 PM, Gustavo Grieco <gustavo.grieco () gmail com>
wrote:

Hello,


We found a write out-of-bounds affecting librsvg 2.40 and cairo 1.14.6


Glenn

Current thread: