CVE-2014-2978: Buffer Overflow
The DispatchWrite function in proxy/dispatcher/idirectfbsurfacedispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2978?
CVE-2014-2978 is classified as a denial-of-service vulnerability that could also allow for arbitrary code execution.
How do I fix CVE-2014-2978?
To address CVE-2014-2978, it is recommended to upgrade DirectFB to a version that has patched the vulnerability.
Which software versions are affected by CVE-2014-2978?
CVE-2014-2978 affects DirectFB version 1.4.4 and various SUSE Linux distributions including openSUSE 13.1 and 13.2.
Can CVE-2014-2978 be exploited remotely?
Yes, CVE-2014-2978 can be exploited remotely via the Voodoo interface to trigger an out-of-bounds write.
What impact does CVE-2014-2978 have on systems?
The impact of CVE-2014-2978 includes potential system crashes and the possibility of executing arbitrary code.