Vulnerability Description
Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultant from an integer overflow in the fast_composite_scaled_bilinear function in pixman-inlines.h, which triggers an infinite loop.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Virtualization | 3.0 |
| Redhat | Enterprise Linux | 6.0 |
| Palemoon | Pale Moon | < 15.4 |
Related Weaknesses (CWE)
References
- http://cgit.freedesktop.org/pixman/commit/?id=de60e2e0e3eb6084f8f14b63f25b3cbfb0Mailing ListPatch
- http://rhn.redhat.com/errata/RHSA-2013-0687.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0746.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:116Broken Link
- http://www.palemoon.org/releasenotes-ng.shtmlBroken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=910149ExploitIssue TrackingPatch
- https://support.f5.com/csp/article/K51392553Third Party Advisory
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0077Third Party Advisory
- http://cgit.freedesktop.org/pixman/commit/?id=de60e2e0e3eb6084f8f14b63f25b3cbfb0Mailing ListPatch
- http://rhn.redhat.com/errata/RHSA-2013-0687.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0746.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:116Broken Link
- http://www.palemoon.org/releasenotes-ng.shtmlBroken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=910149ExploitIssue TrackingPatch
- https://support.f5.com/csp/article/K51392553Third Party Advisory
FAQ
What is CVE-2013-1591?
CVE-2013-1591 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultan...
How severe is CVE-2013-1591?
CVE-2013-1591 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2013-1591?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Virtualization, Redhat Enterprise Linux, Palemoon Pale Moon.