First published: Wed Apr 13 2016(Updated: )
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Libpixman-1-0 | <=0.32.5 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9766 is classified as a critical vulnerability due to its potential to cause application crashes or arbitrary code execution.
To fix CVE-2014-9766, upgrade Pixman to version 0.32.6 or later.
CVE-2014-9766 affects all versions of Pixman prior to 0.32.6.
CVE-2014-9766 impacts Pixman, as well as Ubuntu Linux versions 12.04 and 14.04.
Yes, CVE-2014-9766 can be exploited by remote attackers using specially crafted input to trigger the vulnerability.