{
  "threat_severity" : "Moderate",
  "public_date" : "2016-03-10T00:00:00Z",
  "bugzilla" : {
    "description" : "cairo: out of bounds read in fill_xrgb32_lerp_opaque_spans",
    "id" : "1318977",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1318977"
  },
  "cvss" : {
    "cvss_base_score" : "4.3",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
    "status" : "verified"
  },
  "cwe" : "CWE-839->(CWE-125|CWE-787)",
  "details" : [ "The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a negative span length." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "atk-0:2.14.0-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "cairo-0:1.14.2-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "dconf-0:0.22.0-2.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "gdk-pixbuf2-0:2.31.6-3.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "glib2-0:2.42.2-5.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "glibmm24-0:2.42.0-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "glib-networking-0:2.42.0-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "gobject-introspection-0:1.42.0-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "gtk2-0:2.24.28-8.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "gtk3-0:3.14.13-16.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "gtksourceview3-0:3.14.3-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "harfbuzz-0:0.9.36-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "json-glib-0:1.0.2-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libgsf-0:1.14.26-7.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libnotify-0:0.7.5-8.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libxklavier-0:5.4-7.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "mozjs24-0:24.2.0-6.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "orc-0:0.4.22-5.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "pango-0:1.36.8-2.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "shared-mime-info-0:1.1-9.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-11-19T00:00:00Z",
    "advisory" : "RHBA-2015:2116",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "webkitgtk3-0:2.4.9-5.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "cairo",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "cairo",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2016-3190\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-3190\nhttps://mail.gnome.org/archives/gnome-announce-list/2015-March/msg00047.html" ],
  "name" : "CVE-2016-3190",
  "csaw" : false
}