Vulnerability Description
An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pixman | Pixman | < 0.32.8 |
Related Weaknesses (CWE)
References
- https://bugs.freedesktop.org/show_bug.cgi?id=92027ExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-5297Issue TrackingPatchThird Party Advisory
- https://bugs.freedesktop.org/show_bug.cgi?id=92027ExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-5297Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2015-5297?
CVE-2015-5297 is a vulnerability with a CVSS score of 6.7 (MEDIUM). An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to cra...
How severe is CVE-2015-5297?
CVE-2015-5297 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5297?
Check the references section above for vendor advisories and patch information. Affected products include: Pixman Pixman.