File _patchinfo of Package patchinfo.577

<patchinfo incident="577">
  <issue id="878345" tracker="bnc">VUL-0: CVE-2014-2977: DirectFB: Possible RCE through integer signedness vulnerability</issue>
  <issue id="878349" tracker="bnc">VUL-0: CVE-2014-2978: DirectFB: remote out-of-bounds write vulnerability</issue>
  <issue id="CVE-2014-2978" tracker="cve" />
  <issue id="CVE-2014-2977" tracker="cve" />
  <category>security</category>
  <rating>important</rating>
  <packager>pgajdos</packager>
  <description>DirectFB was updated to fix two security issues.

The following vulnerabilities were fixed:

* CVE-2014-2977: Multiple integer signedness errors could allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.
* CVE-2014-2978: Remote attackers could cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.
</description>
  <summary>Security update for DirectFB</summary>
</patchinfo>
openSUSE Build Service is sponsored by