Security update for DirectFB
DirectFB was updated to fix two security issues.
The following vulnerabilities were fixed:
* CVE-2014-2977: Multiple integer signedness errors could allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.
* CVE-2014-2978: Remote attackers could cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.
-
Submitted by
Petr Gajdos (pgajdos)
Fixed bugs
bnc#878345
VUL-0: CVE-2014-2977: DirectFB: Possible RCE through integer signedness vulnerability
bnc#878349
VUL-0: CVE-2014-2978: DirectFB: remote out-of-bounds write vulnerability