PT-2013-1192 · Moonchild Productions+4 · Pale Moon+4
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pale Moon versions prior to 15.4
libpixman version 0.26.2
Description
The issue is related to a stack-based buffer overflow in libpixman, which may have unspecified impact and context-dependent attack vectors. It might be resultant from an integer overflow in the
fast composite scaled bilinear function in pixman-inlines.h, triggering an infinite loop. The vulnerability can be exploited remotely and may lead to disruption of confidentiality, integrity, and availability of protected information.Recommendations
For Pale Moon versions prior to 15.4, update to version 15.4 or later.
For libpixman version 0.26.2, consider disabling the
fast composite scaled bilinear function as a temporary workaround until a patch is available.
Restrict access to the vulnerable libpixman module to minimize the risk of exploitation.Exploit
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Pale Moon
Red Hat
Suse
Libpixman