DirectFB Dispatch_Write Buffer Overflow Vulnerability (CVE-2014-2977)
Release date:
Updated on:
Affected Systems:
Directfb 1.4.13
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-2977
DirectFB is a lightweight graphics library that provides hardware graphics acceleration, input device processing, and abstraction. It integrates a translucent windows system and multi-layer display on the LinuxFramebuffer driver.
Multiple Integer signature errors exist in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c of DirectFB 1.4.13. Remote attackers can exploit this vulnerability through the Voodoo interface to cause DoS and execute arbitrary code.
<* Source: Frederic Basse
Link: http://secunia.com/advisories/58448
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Directfb
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://directfb.org/
This article permanently updates the link address: