Lucene search

K
cve[email protected]CVE-2014-2978
HistoryJun 11, 2014 - 2:55 p.m.

CVE-2014-2978

2014-06-1114:55:07
CWE-119
web.nvd.nist.gov
25
cve-2014-2978
directfb 1.4.4
denial of service
remote attackers
execute arbitrary code
out-of-bounds write

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.034 Low

EPSS

Percentile

91.4%

The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.

Affected configurations

NVD
Node
directfbdirectfbMatch1.4.4
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
OR
suselinux_enterprise_desktopMatch12
OR
suselinux_enterprise_software_development_kitMatch12
OR
suselinux_enterprise_workstation_extensionMatch12
OR
susesuse_linux_enterprise_serverMatch12
CPENameOperatorVersion
directfb:directfbdirectfbeq1.4.4

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.034 Low

EPSS

Percentile

91.4%