Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.
An Out-of-bounds memory read / write flaw was found in Mesa. A remote attacker could use this flaw to crash an application linked against or, potentially, execute arbitrary code via an application linked against Mesa graphics libraries.
References:
https://bugs.freedesktop.org/showbug.cgi?id=59429 https://code.google.com/p/chromium/issues/detail?id=169054 (private) https://bugzilla.mozilla.org/showbug.cgi?id=827106 (private)