]> code.ossystems Code Review - openembedded-core.git/commit
xorg: Fix for CVE-2013-6424
authorKai Kang <kai.kang@windriver.com>
Tue, 1 Apr 2014 09:09:50 +0000 (17:09 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 1 Apr 2014 10:25:47 +0000 (11:25 +0100)
commit059dc5f4ef9bcf49cb6520f5f2ab1e739f4d42de
treee984f5c681bd1cfad55f594bf21ca62ec52ece7c
parentc93eeecb15c4acac9226a3394c93d7e99a809d6b
xorg: Fix for CVE-2013-6424

Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org
allows context-dependent attackers to cause a denial of service (crash) via
a negative bottom value.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6424

Signed-off-by: Baogen Shang <baogen.shang@windriver.com>
Signed-off-by: Kai Kang <kai.kang@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-graphics/xorg-xserver/xserver-xorg/xorg-CVE-2013-6424.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-xserver/xserver-xorg_1.15.0.bb