CVE-2014-2978

DirectFB 1.4.4 - Remote Code Execution via Voodoo Interface Out-of-Bounds Write

Title source: llm
STIX 2.1

Description

The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.

References (8)

Core 8
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:223
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201701-55
Various Sources mailing-list x_refsource_mlist
http://mail.directfb.org/pipermail/directfb-dev/2014-March/006805.html
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2015-0176.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/05/15/10
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58448

Scores

EPSS 0.0814
EPSS Percentile 92.3%

Details

CWE
CWE-119
Status published
Products (7)
directfb/directfb 1.4.4
opensuse/opensuse 13.1
opensuse/opensuse 13.2
suse/linux_enterprise_desktop 12
suse/linux_enterprise_software_development_kit 12
suse/linux_enterprise_workstation_extension 12
suse/suse_linux_enterprise_server 12
Published Jun 11, 2014
Tracked Since Feb 18, 2026