https://bugzilla.redhat.com/show_bug.cgi?id=1311882

            Bug ID: 1311882
           Summary: CVE-2014-9766 pixman: integer overflow in create_bits
                    function
           Product: Security Response
         Component: vulnerability
          Keywords: Security
          Severity: medium
          Priority: medium
          Assignee: security-response-t...@redhat.com
          Reporter: ane...@redhat.com
                CC: a...@redhat.com, alo...@redhat.com,
                    bmccl...@redhat.com, cferg...@redhat.com,
                    dblec...@redhat.com, erik-fed...@vanpienbroek.nl,
                    fedora-mi...@lists.fedoraproject.org,
                    gkl...@redhat.com, lsure...@redhat.com,
                    mgold...@redhat.com, michal.skriva...@redhat.com,
                    ogab...@redhat.com, rbala...@redhat.com,
                    rh-spice-b...@redhat.com, rjo...@redhat.com,
                    sher...@redhat.com, yd...@redhat.com,
                    yey...@redhat.com, yk...@redhat.com




In create_bits() both height and stride are ints, so the result is
also an int, which will overflow if height or stride are big enough
and size_t is bigger than int.

External references:

https://web.archive.org/web/20141227044037/http://lists.freedesktop.org/archives/pixman/2014-April/003244.html

CVE assignment:

http://seclists.org/oss-sec/2016/q1/425

-- 
You are receiving this mail because:
You are on the CC list for the bug.
_______________________________________________
mingw mailing list
mingw@lists.fedoraproject.org
http://lists.fedoraproject.org/admin/lists/mingw@lists.fedoraproject.org

Reply via email to