|
|
Log in / Subscribe / Register

DirectFB: two vulnerabilities

Package(s):DirectFB CVE #(s):CVE-2014-2977 CVE-2014-2978
Created:April 30, 2015 Updated:January 23, 2017
Description: From the CVE entries:

Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow. (CVE-2014-2977)

The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write. (CVE-2014-2978)

Alerts:
Gentoo 201701-55 DirectFB 2017-01-23
SUSE SUSE-SU-2015:0839-1 DirectFB 2015-05-08
Mandriva MDVSA-2015:223 directfb 2015-05-04
Mageia MGASA-2015-0176 directfb 2015-05-03
openSUSE openSUSE-SU-2015:0807-1 DirectFB 2015-04-30

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds