PT-2014-1961 · None+2 · Pixman+2

Søren Sandmann

·

Published

2014-09-05

·

Updated

2016-12-03

·

CVE-2014-9766

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pixman versions prior to 0.32.6
Description The issue is caused by an integer overflow in the create bits function in pixman-bits-image.c. This can be exploited by a remote attacker to cause a denial of service, resulting in the application crashing, or possibly to execute arbitrary code. The exploitation is facilitated by large height and stride values.
Recommendations For versions prior to 0.32.6, update to version 0.32.6 or later to resolve the issue. As a temporary workaround, consider restricting the input values for height and stride to prevent large values from being processed by the create bits function.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2079
BDU:2016-01651
CVE-2014-9766
DLA-429-1
DSA-3525-1
USN-2918-1

Affected Products

Alt Linux
Pixman
Ubuntu