cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
| Software | From | Fixed in |
|---|---|---|
| cairographics / cairo | - | 1.15.6.x |
| opensuse / leap | 15.1 | 15.1.x |