CVE-2014-2977
published 2014-06-11CVE-2014-2977: Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.78%
93.2th percentile
Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | directfb | — | — |
| directfb | directfb | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian10.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r25x-m6r4-r5pf: Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher
ghsa_unreviewed·2022-05-14
CVE-2014-2977 [HIGH] GHSA-r25x-m6r4-r5pf: Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher
Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.
Debian
CVE-2014-2977: directfb - Multiple integer signedness errors in the Dispatch_Write function in proxy/dispa...
vendor_debian·2014·CVSS 10.0
CVE-2014-2977 [CRITICAL] CVE-2014-2977: directfb - Multiple integer signedness errors in the Dispatch_Write function in proxy/dispa...
Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.
Scope: local
bookworm: resolved
bullseye: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2977 DirectFB: integer signedness vulnerability
bugzilla·2014-05-16·CVSS 10.0
CVE-2014-2977 [CRITICAL] CVE-2014-2977 DirectFB: integer signedness vulnerability
CVE-2014-2977 DirectFB: integer signedness vulnerability
DirectFB is prone to an integer signedness vulnerability since version 1.4.13.
The vulnerability can be triggered remotely without authentication through Voodoo interface (network layer of DirectFB).
This integer coercion error may lead to a stack overflow.
Patches are availble from [2]
References:
[1]: http://seclists.org/oss-sec/2014/q2/322
[2]: http://mail.directfb.org/pipermail/directfb-dev/2014-March/006805.html
Discussion:
Created directfb tracking bugs for this issue:
Affects: fedora-all [bug 1098546]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual com
Bugzilla
CVE-2014-2977 DirectFB: integer signedness vulnerability [fedora-all]
bugzilla·2014-05-16·CVSS 10.0
CVE-2014-2977 [CRITICAL] CVE-2014-2977 DirectFB: integer signedness vulnerability [fedora-all]
CVE-2014-2977 DirectFB: integer signedness vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supporte
http://advisories.mageia.org/MGASA-2015-0176.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00003.htmlhttp://mail.directfb.org/pipermail/directfb-dev/2014-March/006805.htmlhttp://secunia.com/advisories/58448http://www.mandriva.com/security/advisories?name=MDVSA-2015:223http://www.openwall.com/lists/oss-security/2014/05/15/9https://security.gentoo.org/glsa/201701-55http://advisories.mageia.org/MGASA-2015-0176.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00003.htmlhttp://mail.directfb.org/pipermail/directfb-dev/2014-March/006805.htmlhttp://secunia.com/advisories/58448http://www.mandriva.com/security/advisories?name=MDVSA-2015:223http://www.openwall.com/lists/oss-security/2014/05/15/9https://security.gentoo.org/glsa/201701-55
2014-06-11
Published