summaryrefslogtreecommitdiff
path: root/include
diff options
context:
space:
mode:
authorAlan Coopersmith <alan.coopersmith@oracle.com>2013-04-13 00:16:14 -0700
committerAlan Coopersmith <alan.coopersmith@oracle.com>2013-05-07 14:04:08 -0700
commit15ab7dec17d686c38f2c82ac23a17cac5622322a (patch)
treeecf3f834d59b8157cf0cd326f7d2f213455a96d8 /include
parent6e1b743a276651195be3cd68dff41e38426bf3ab (diff)
buffer overflow in XvQueryPortAttributes() [CVE-2013-2066]
Each attribute returned in the reply includes the number of bytes to read for its marker. We had been always trusting it, and never validating that it wouldn't cause us to write past the end of the buffer we allocated based on the reported text_size. Reported-by: Ilja Van Sprundel <ivansprundel@ioactive.com> Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com>
Diffstat (limited to 'include')
0 files changed, 0 insertions, 0 deletions