CVE-2019-6245: Antigrain Agg
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call itself recursively. There can be a situation where (x2 - x1) is always bigger than dx_limit during the recursion, leading to continual stack consumption.
Affected products
- Antigrain Agg: version 2.4 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Svgpp Svgpp: version 1.2.3 only
Published 2019-01-13. Last modified 2026-06-17.