MEDIUM · 5.0

CVE-2013-6425

Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) vi...

Vulnerability Description

Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
PixmanPixman< 0.32.0
CanonicalUbuntu Linux12.04
DebianDebian Linux6.0
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus6.5
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Aus6.5
RedhatEnterprise Linux Server Tus6.5
RedhatEnterprise Linux Workstation5.0
OpensuseOpensuse11.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-6425?

CVE-2013-6425 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) vi...

How severe is CVE-2013-6425?

CVE-2013-6425 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-6425?

Check the references section above for vendor advisories and patch information. Affected products include: Pixman Pixman, Canonical Ubuntu Linux, Debian Debian Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus.