MGASA-2015-0176
Dashboard / Vulnerabilities / MGASA-2015-0176
Summary: Updated directfb packages fix security vulnerabilities
Details: Updated directfb packages fix security vulnerabilities: Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow (CVE-2014-2977). The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write (CVE-2014-2978).
References: https://advisories.mageia.org/MGASA-2015-0176.html, https://bugs.mageia.org/show_bug.cgi?id=13391, http://lists.opensuse.org/opensuse-updates/2015-04/msg00060.html
Affected packages
Package
Name: directfb
Purl: pkg:rpm/mageia/directfb?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
