cbcvebase.
CVE-2019-6245
published 2019-01-13

CVE-2019-6245: An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 -…

PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.95%
78.3th percentile
An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call itself recursively. There can be a situation where (x2 - x1) is always bigger than dx_limit during the recursion, leading to continual stack consumption.

Affected

10 ranges
VendorProductVersion rangeFixed in
antigrainagg
antigrainagg>= 0 < 1:2.4-r127+dfsg1-11:2.4-r127+dfsg1-1
antigrainagg>= 0 < 1:2.4-r127+dfsg1-11:2.4-r127+dfsg1-1
antigrainagg>= 0 < 1:2.4-r127+dfsg1-11:2.4-r127+dfsg1-1
antigrainagg>= 0 < 1:2.4-r127+dfsg1-11:2.4-r127+dfsg1-1
debianagg< agg 1:2.4-r127+dfsg1-1 (bookworm)agg 1:2.4-r127+dfsg1-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiansvgpp< agg 1:2.4-r127+dfsg1-1 (bookworm)agg 1:2.4-r127+dfsg1-1 (bookworm)
svgppsvgpp

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.