{"id":"JLSEC-2025-17","summary":"A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4","details":"A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -\u003e out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.","modified":"2025-11-06T23:02:42.254676Z","published":"2025-10-10T13:22:08.213Z","upstream":["CVE-2020-35492"],"database_specific":{"license":"CC-BY-4.0","sources":[{"published":"2021-03-18T19:15:13.230Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2020-35492","id":"CVE-2020-35492","modified":"2024-11-21T05:27:24.803Z","imported":"2025-10-09T21:00:34.751Z","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2020-35492"}]},"references":[{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1898396"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-21"}],"affected":[{"package":{"name":"Cairo_jll","ecosystem":"Julia","purl":"pkg:julia/Cairo_jll?uuid=83423d85-b0ee-5818-9007-b63ccbeb887a"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.18.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-17.json"}}],"schema_version":"1.7.3"}