CVE-2014-9766: Integer Overflow
Published Apr 13, 2016
·Updated
Integer overflow in the createbits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.
Affected Software
3 affected components
pixman pixman<=0.32.5
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Remediation
Event History
Apr 13, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9766?
CVE-2014-9766 is classified as a critical vulnerability due to its potential to cause application crashes or arbitrary code execution.
2
How do I fix CVE-2014-9766?
To fix CVE-2014-9766, upgrade Pixman to version 0.32.6 or later.
3
Which versions of Pixman are affected by CVE-2014-9766?
CVE-2014-9766 affects all versions of Pixman prior to 0.32.6.
4
What specific software releases are known to be impacted by CVE-2014-9766?
CVE-2014-9766 impacts Pixman, as well as Ubuntu Linux versions 12.04 and 14.04.
5
Can CVE-2014-9766 be exploited remotely?
Yes, CVE-2014-9766 can be exploited by remote attackers using specially crafted input to trigger the vulnerability.