[CVE-2016-3190] Fix CVE issue 04/275304/1 accepted/tizen_7.0_unified accepted/tizen_7.0_unified_hotfix accepted/tizen_8.0_unified accepted/tizen_unified tizen_7.0_hotfix tizen_8.0 accepted/tizen/7.0/unified/20221110.060803 accepted/tizen/7.0/unified/hotfix/20221116.105307 accepted/tizen/8.0/unified/20231005.093331 accepted/tizen/unified/20220728.131651 submit/tizen/20220520.082748 submit/tizen/20220727.012456 submit/tizen/20221109.014223 tizen_7.0_m2_release tizen_8.0_m2_release
authortscholb <scholb.kim@samsung.com>
Fri, 20 May 2022 08:01:21 +0000 (17:01 +0900)
committertscholb <scholb.kim@samsung.com>
Fri, 20 May 2022 08:01:21 +0000 (17:01 +0900)
commitffa067b0f650e8732269f8b01652b928ad8e311f
tree75578fa373b06a95451083748016af9d8ac2c42d
parentef01c6ac4a970a9af2d5d583c65e5253d518472e
[CVE-2016-3190] Fix CVE issue

The fill_xrgb32_lerp_opaque_spans() allows remote attackers to cause a denial of service
(out-of-bounds read and application crash) via a negative span length.

Change-Id: Iebce4b5d6fd9ea6435cc88875f314fb60d81bddd
src/cairo-image-compositor.c