Bugzilla – Bug 968090
VUL-1: CVE-2014-9766: pixman: create_bits(): Cast the result of height * stride to size_t
Last modified: 2024-05-07 14:37:44 UTC
http://seclists.org/oss-sec/2016/q1/425 There is an (old) integer overflow in create_bits in the pixman library. https://web.archive.org/web/20141227044037/http://lists.freedesktop.org/archives/pixman/2014-April/003244.html https://bugzilla.redhat.com/show_bug.cgi?id=972647 Use CVE-2014-9766. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9766 http://seclists.org/oss-sec/2016/q1/425 https://bugs.freedesktop.org/attachment.cgi?id=85448 https://bugs.freedesktop.org/show_bug.cgi?id=69014 https://lists.freedesktop.org/archives/pixman/2013-September/002915.html
openSUSE Leap and 13.2 is already fixed for this one, so I guess this is a SLE only bug. Thu Jul 10 20:09:28 UTC 2014 - dimstar@ - Update to version 0.32.6: + MIPS: Fix exported symbols in public API. + build: Check if the compiler supports GCC vector extensions. + Bugs fixed: rh#972647, fdo#69014.
(In reply to Bjørn Lie from comment #2) > openSUSE Leap and 13.2 is already fixed for this one, so I guess this is a > SLE only bug. You should perhaps ping the evergreen team to check if they need to push a fix?
bugbot adjusting priority
SLE 12 has version 0.32.6. I think that it's only SLE-11-SP3 and SLE-11-SP1 that are affected.
All done, closing.