PT-2013-1076 · Pixman+4 · Pixman+4

Bryan Quigley

·

Publicado

2013-11-12

·

Atualizado

2023-02-13

·

CVE-2013-6425

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions pixman versions prior to 0.32.0 pixman version 0.22.0
Description The issue is related to an integer underflow in the pixman trapezoid valid macro in pixman.h in Pixman, which can be exploited to cause a denial of service (crash) via a negative bottom value. This can lead to disruption of protected information and can be exploited remotely.
Recommendations For pixman versions prior to 0.32.0, update to version 0.32.0 or later to resolve the issue. For pixman version 0.22.0, consider disabling the pixman trapezoid valid macro until a patch is available. As a temporary workaround, restrict access to the vulnerable pixman package to minimize the risk of exploitation.

Correção

DoS

Integer Underflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1095
BDU:2015-02538
BDU:2015-07073
BDU:2015-07074
BDU:2015-07075
BDU:2015-09073
BDU:2015-09074
BDU:2015-09075
BDU:2015-09752
CESA-2013_1869
CVE-2013-6425
DSA-2823-1
MGASA-2013-0366
RHSA-2013:1869
RHSA-2013_1869
SUSE-SU-2014_0023-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Pixman