CVE-2014-2978
published 2014-06-11CVE-2014-2978: The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash)…
PriorityP344critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.10%
92.6th percentile
The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | directfb | — | — |
| directfb | directfb | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian10.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-2978: directfb - The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in...
vendor_debian·2014·CVSS 10.0
CVE-2014-2978 [CRITICAL] CVE-2014-2978: directfb - The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in...
The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.
Scope: local
bookworm: resolved
bullseye: resolved
GHSA
GHSA-c84x-q5hx-4xvc: The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher
ghsa_unreviewed·2022-05-14
CVE-2014-2978 [HIGH] CWE-119 GHSA-c84x-q5hx-4xvc: The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher
The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability [epel-all]
bugzilla·2014-05-16·CVSS 10.0
CVE-2014-2978 [CRITICAL] CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability [epel-all]
CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multip
Bugzilla
CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability
bugzilla·2014-05-16·CVSS 10.0
CVE-2014-2978 [CRITICAL] CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability
CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability
It was reproted [1] that DirectFB is prone to an out-of-bound write vulnerability since version 1.4.4.
The vulnerability can be triggered remotely without authentication through Voodoo interface (network layer of DirectFB).
An attacker can choose to overflow in the heap or the stack.
Upstream patch is available on [2].
References:
[1]: http://seclists.org/oss-sec/2014/q2/323
[2]: http://mail.directfb.org/pipermail/directfb-dev/2014-March/006805.html
Discussion:
Created directfb tracking bugs for this issue:
Affects: fedora-all [bug 1098542]
Affects: epel-all [bug 1098543]
---
I have built a patch for this issue, roughly based on the patch that OpenSuSE submitted upstream at http://mail.directfb.org/pipermail/directf
Bugzilla
CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability [fedora-all]
bugzilla·2014-05-16·CVSS 10.0
CVE-2014-2978 [CRITICAL] CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability [fedora-all]
CVE-2014-2978 DirectFB: remote out-of-bounds write vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple
http://advisories.mageia.org/MGASA-2015-0176.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00003.htmlhttp://mail.directfb.org/pipermail/directfb-dev/2014-March/006805.htmlhttp://secunia.com/advisories/58448http://www.mandriva.com/security/advisories?name=MDVSA-2015:223http://www.openwall.com/lists/oss-security/2014/05/15/10https://security.gentoo.org/glsa/201701-55http://advisories.mageia.org/MGASA-2015-0176.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00003.htmlhttp://mail.directfb.org/pipermail/directfb-dev/2014-March/006805.htmlhttp://secunia.com/advisories/58448http://www.mandriva.com/security/advisories?name=MDVSA-2015:223http://www.openwall.com/lists/oss-security/2014/05/15/10https://security.gentoo.org/glsa/201701-55
2014-06-11
Published