File _patchinfo of Package patchinfo.577
<patchinfo incident="577"> <issue id="878345" tracker="bnc">VUL-0: CVE-2014-2977: DirectFB: Possible RCE through integer signedness vulnerability</issue> <issue id="878349" tracker="bnc">VUL-0: CVE-2014-2978: DirectFB: remote out-of-bounds write vulnerability</issue> <issue id="CVE-2014-2978" tracker="cve" /> <issue id="CVE-2014-2977" tracker="cve" /> <category>security</category> <rating>important</rating> <packager>pgajdos</packager> <description>DirectFB was updated to fix two security issues. The following vulnerabilities were fixed: * CVE-2014-2977: Multiple integer signedness errors could allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow. * CVE-2014-2978: Remote attackers could cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write. </description> <summary>Security update for DirectFB</summary> </patchinfo>