{"id":"GHSA-5v3f-73gv-x7x5","summary":"cairo is vulnerable to denial of service due to a null pointer dereference","details":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the `FT_Load_Glyph` and `FT_Render_Glyph` resulting in an application crash.","aliases":["CVE-2017-7475"],"modified":"2026-04-24T06:41:25.058209069Z","published":"2017-11-15T20:41:14Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:17:22Z","nvd_published_at":"2017-05-19T20:29:00Z","cwe_ids":["CWE-476"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475"},{"type":"WEB","url":"https://bugs.freedesktop.org/show_bug.cgi?id=100763"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475"},{"type":"PACKAGE","url":"https://github.com/rcairo/rcairo"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cairo/CVE-2017-7475.yml"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"},{"type":"WEB","url":"http://seclists.org/oss-sec/2017/q2/151"}],"affected":[{"package":{"name":"cairo","ecosystem":"RubyGems","purl":"pkg:gem/cairo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.15.4"},{"fixed":"1.15.5"}]}],"versions":["1.15.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/11/GHSA-5v3f-73gv-x7x5/GHSA-5v3f-73gv-x7x5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}