CVE-2018-19876 describes a memory corruption vulnerability in cairo 1.16.0, specifically within the cairo_ft_apply_variations() function, affecting the cairographics cairo library. This flaw occurs when an incompatible free function is used with WebKit's fastMalloc, leading to an application crash (denial of service) with an "invalid pointer" error. Rated Medium severity (CVSS 6.5), it requires user interaction (UI:R) and network access (AV:N) for exploitation, but has low attack complexity (AC:L). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.16.0CPE matchmatch criteria | cpe:2.3:a:cairographics:cairo:1.16.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-19876
Aug 11, 2020cairo 1.16.0 in cairo_ft_apply_variations() in cairo-ft-font.c would free memory using a free function incompatible with WebKit's fastMalloc leading to an application crash with a "free(): invalid pointer" error.
Dec 11, 2018cairo: Invalid free in cairo_ft_apply_variations() resulting in a denial of service
Nov 13, 2018