CVE-2013-6425
published 2014-01-18CVE-2013-6425: Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.88%
85.4th percentile
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | pixman | < pixman 0.30.2-2 (bookworm) | pixman 0.30.2-2 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| pixman | pixman | < 0.32.0 | 0.32.0 |
| pixman | pixman | >= 0 < 0.30.2-2 | 0.30.2-2 |
| pixman | pixman | >= 0 < 0.30.2-2 | 0.30.2-2 |
| pixman | pixman | >= 0 < 0.30.2-2 | 0.30.2-2 |
| pixman | pixman | >= 0 < 0.30.2-2 | 0.30.2-2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pixman: integer underflow when handling trapezoids
vendor_redhat·2013-07-16·CVSS 5.0
CVE-2013-6425 [MEDIUM] CWE-190 pixman: integer underflow when handling trapezoids
pixman: integer underflow when handling trapezoids
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Package: qpixman (Red Hat Enterprise Linux 5) - Not affected
Package: pixman (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6425: pixman - Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman befo...
vendor_debian·2013·CVSS 5.0
CVE-2013-6425 [MEDIUM] CVE-2013-6425: pixman - Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman befo...
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Scope: local
bookworm: resolved (fixed in 0.30.2-2)
bullseye: resolved (fixed in 0.30.2-2)
forky: resolved (fixed in 0.30.2-2)
sid: resolved (fixed in 0.30.2-2)
trixie: resolved (fixed in 0.30.2-2)
GHSA
GHSA-pm7m-xq2w-2q3x: Integer underflow in the pixman_trapezoid_valid macro in pixman
ghsa_unreviewed·2022-05-13
CVE-2013-6425 [MEDIUM] CWE-191 GHSA-pm7m-xq2w-2q3x: Integer underflow in the pixman_trapezoid_valid macro in pixman
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
OSV
CVE-2013-6425: Integer underflow in the pixman_trapezoid_valid macro in pixman
osv·2014-01-18·CVSS 5.0
CVE-2013-6425 [MEDIUM] CVE-2013-6425: Integer underflow in the pixman_trapezoid_valid macro in pixman
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6425 mingw-pixman: pixman: integer underflow when handling trapezoids [fedora-all]
bugzilla·2013-12-17·CVSS 5.0
CVE-2013-6425 [MEDIUM] CVE-2013-6425 mingw-pixman: pixman: integer underflow when handling trapezoids [fedora-all]
CVE-2013-6425 mingw-pixman: pixman: integer underflow when handling trapezoids [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-6425 pixman: integer underflow when handling trapezoids [fedora-all]
bugzilla·2013-12-17·CVSS 5.0
CVE-2013-6425 [MEDIUM] CVE-2013-6425 pixman: integer underflow when handling trapezoids [fedora-all]
CVE-2013-6425 pixman: integer underflow when handling trapezoids [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-6425 mingw32-pixman: pixman: integer underflow when handling trapezoids [epel-5]
bugzilla·2013-12-17·CVSS 5.0
CVE-2013-6425 [MEDIUM] CVE-2013-6425 mingw32-pixman: pixman: integer underflow when handling trapezoids [epel-5]
CVE-2013-6425 mingw32-pixman: pixman: integer underflow when handling trapezoids [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tra
Bugzilla
CVE-2013-6425 pixman: integer underflow when handling trapezoids
bugzilla·2013-12-04·CVSS 5.0
CVE-2013-6425 [MEDIUM] CVE-2013-6425 pixman: integer underflow when handling trapezoids
CVE-2013-6425 pixman: integer underflow when handling trapezoids
An integer underflow flaw was found in pixman when handling trapezoids. If an application used pixman opened a crafted document, it could cause the application to crash.
References:
http://seclists.org/oss-sec/2013/q4/399
https://bugs.freedesktop.org/show_bug.cgi?id=67484
https://bugs.freedesktop.org/attachment.cgi?id=87925
Discussion:
CVE request: http://www.openwall.com/lists/oss-security/2013/12/03/8
---
Adam,
If you look at the valgrind output from the above reproducer, there is an invalid read and an invalid write on the heap, which really seems to be user controllable. Looking at the code the issue is in pixman/pixman-edge.c:
210 WRITE (image, ap + lxi,
211 clip255 (READ (image, ap + lxi) + rxs - lxs));
This le
http://cgit.freedesktop.org/pixman/commit/?id=5e14da97f16e421d084a9e735be21b1025150f0chttp://lists.freedesktop.org/archives/pixman/2013-November/003109.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00097.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1869.htmlhttp://www.debian.org/security/2013/dsa-2823http://www.openwall.com/lists/oss-security/2013/12/03/8http://www.openwall.com/lists/oss-security/2013/12/04/8http://www.ubuntu.com/usn/USN-2047-1https://bugs.freedesktop.org/show_bug.cgi?id=67484https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/1197921http://cgit.freedesktop.org/pixman/commit/?id=5e14da97f16e421d084a9e735be21b1025150f0chttp://lists.freedesktop.org/archives/pixman/2013-November/003109.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00097.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1869.htmlhttp://www.debian.org/security/2013/dsa-2823http://www.openwall.com/lists/oss-security/2013/12/03/8http://www.openwall.com/lists/oss-security/2013/12/04/8http://www.ubuntu.com/usn/USN-2047-1https://bugs.freedesktop.org/show_bug.cgi?id=67484https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/1197921
2014-01-18
Published