Lucene search

K
suseSuseSUSE-SU-2015:0839-1
HistoryMay 08, 2015 - 3:05 p.m.

Security update for DirectFB (important)

2015-05-0815:05:45
lists.opensuse.org
7

0.036 Low

EPSS

Percentile

91.6%

DirectFB was updated to fix two security issues.

The following vulnerabilities were fixed:

  • CVE-2014-2977: Multiple integer signedness errors could allow remote
    attackers to cause a denial of service (crash) and possibly execute
    arbitrary code via the Voodoo interface, which triggers a stack-based
    buffer overflow.
  • CVE-2014-2978: Remote attackers could cause a denial of service (crash)
    and possibly execute arbitrary code via the Voodoo interface, which
    triggers an out-of-bounds write.