DirectFB: two vulnerabilities
| Package(s): | DirectFB | CVE #(s): | CVE-2014-2977 CVE-2014-2978 | ||||||||||||||||||||
| Created: | April 30, 2015 | Updated: | January 23, 2017 | ||||||||||||||||||||
| Description: | From the CVE entries:
Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow. (CVE-2014-2977) The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write. (CVE-2014-2978) | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
