Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bryan Quigley

#22261of 53,638
10Total CVSS
Vulnerabilities · 2
Medium
2
PT-2013-1076
5.0
2013-11-12
Pixman · Pixman · CVE-2013-6425
**Name of the Vulnerable Software and Affected Versions** pixman versions prior to 0.32.0 pixman version 0.22.0 **Description** The issue is related to an integer underflow in the `pixman trapezoid valid` macro in `pixman.h` in Pixman, which can be exploited to cause a denial of service (crash) via a negative bottom value. This can lead to disruption of protected information and can be exploited remotely. **Recommendations** For pixman versions prior to 0.32.0, update to version 0.32.0 or later to resolve the issue. For pixman version 0.22.0, consider disabling the `pixman trapezoid valid` macro until a patch is available. As a temporary workaround, restrict access to the vulnerable `pixman` package to minimize the risk of exploitation.
PT-2014-3109
5.0
2013-11-12
X.Org · X.Org · CVE-2013-6424
**Name of the Vulnerable Software and Affected Versions** X.Org (affected versions not specified) **Description** The issue is related to an integer underflow in the xTrapezoidValid macro, which can be exploited by context-dependent attackers to cause a denial of service, resulting in a crash. This can be achieved by providing a negative bottom value. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.