Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pixman | Pixman | * | 0.31.2 (excluding) |
Red Hat Enterprise Linux 5 | RedHat | xorg-x11-server-0:1.1.1-48.101.el5_10.2 | * |
Red Hat Enterprise Linux 6 | RedHat | xorg-x11-server-0:1.13.0-23.1.el6_5 | * |
Xorg-server | Ubuntu | lucid | * |
Xorg-server | Ubuntu | precise | * |
Xorg-server | Ubuntu | quantal | * |
Xorg-server | Ubuntu | raring | * |
Xorg-server | Ubuntu | upstream | * |