PT-2014-1961 · None+2 · Pixman+2

Søren Sandmann

·

Publicado

2014-09-05

·

Atualizado

2016-12-03

·

CVE-2014-9766

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pixman versions prior to 0.32.6
Description The issue is caused by an integer overflow in the create bits function in pixman-bits-image.c. This can be exploited by a remote attacker to cause a denial of service, resulting in the application crashing, or possibly to execute arbitrary code. The exploitation is facilitated by large height and stride values.
Recommendations For versions prior to 0.32.6, update to version 0.32.6 or later to resolve the issue. As a temporary workaround, consider restricting the input values for height and stride to prevent large values from being processed by the create bits function.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2079
BDU:2016-01651
CVE-2014-9766
DLA-429-1
DSA-3525-1
USN-2918-1

Produtos afetados

Alt Linux
Pixman
Ubuntu