MEDIUM · 6.8

CVE-2007-5503

Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image with large width and height values, which is not pro...

Vulnerability Description

Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image with large width and height values, which is not properly handled by the read_png function.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
RedhatCairo<= 1.4.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5503?

CVE-2007-5503 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image with large width and height values, which is not pro...

How severe is CVE-2007-5503?

CVE-2007-5503 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5503?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Cairo.