Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pixman | Pixman | * | 0.32.0 (excluding) |
Pixman | Ubuntu | lucid | * |
Pixman | Ubuntu | precise | * |
Pixman | Ubuntu | quantal | * |
Pixman | Ubuntu | raring | * |
Pixman | Ubuntu | saucy | * |
Pixman | Ubuntu | upstream | * |
Red Hat Enterprise Linux 5 | RedHat | pixman-0:0.22.0-2.2.el5_10 | * |
Red Hat Enterprise Linux 6 | RedHat | pixman-0:0.26.2-5.1.el6_5 | * |