CVE-2019-6462 describes an infinite loop vulnerability in cairo version 1.16.0, specifically within the _arc_error_normalized function in cairo-arc.c. This medium-severity flaw (CVSS 6.5) can be triggered remotely with low attack complexity, requiring user interaction, and could lead to a denial of service (availability impact). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.16.0CPE matchmatch criteria | cpe:2.3:a:cairographics:cairo:1.16.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-6462
Aug 11, 2020cairo: infinite loop in the function _arc_error_normalized in the file cairo-arc.c
Jan 11, 2019An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c related to _arc_max_angle_for_tolerance_normalized.
Jan 8, 2019