CVE-2019-6462Infinite Loop in Cairo

CWE-835Infinite Loop14 documents8 sources
Severity
6.5MEDIUMNVD
OSV7.5OSV5.5
EPSS
0.1%
top 83.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateApr 2

Description

An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

debiandebian/cairo< cairo 1.17.8-3 (forky)
Debiancairographics/cairo< 1.17.8-3+1
Ubuntucairographics/cairo< 1.16.0-5ubuntu2.1+4

🔴Vulnerability Details

4
OSV
cairo vulnerabilities2026-04-02
GHSA
GHSA-7m29-23h6-ccwp: An issue was discovered in cairo 12022-05-13
OSV
cairo vulnerabilities2022-05-10
OSV
CVE-2019-6462: An issue was discovered in cairo 12019-01-16

📋Vendor Advisories

5
Ubuntu
Cairo vulnerabilities2026-04-02
Ubuntu
Cairo vulnerabilities2022-05-10
Red Hat
cairo: infinite loop in the function _arc_error_normalized in the file cairo-arc.c2019-01-11
Microsoft
An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c related to _arc_max_angle_for_tolerance_normalized.2019-01-08
Debian
CVE-2019-6462: cairo - An issue was discovered in cairo 1.16.0. There is an infinite loop in the functi...2019

💬Community

4
Bugzilla
CVE-2019-6462 cairo: infinite loop in the function _arc_error_normalized in the file cairo-arc.c2019-01-31
Bugzilla
CVE-2019-6462 mingw-cairo: cairo: infinite loop in the function _arc_error_normalized in the file cairo-arc.c [fedora-all]2019-01-31
Bugzilla
CVE-2019-6462 mingw-cairo: cairo: infinite loop in the function _arc_error_normalized in the file cairo-arc.c [epel-7]2019-01-31
Bugzilla
CVE-2019-6462 cairo: infinite loop in the function _arc_error_normalized in the file cairo-arc.c [fedora-all]2019-01-31