diff options
author | Alan Coopersmith <alan.coopersmith@oracle.com> | 2013-03-10 13:30:55 -0700 |
---|---|---|
committer | Alan Coopersmith <alan.coopersmith@oracle.com> | 2013-05-23 08:13:26 -0700 |
commit | 17071c1c608247800b2ca03a35b1fcc9c4cabe6c (patch) | |
tree | c87ff8e4a349da759782bb4e0ad05656d2b30d5c /specs/library.xml | |
parent | 528419b9ef437e7eeafb41bf45e8ff7d818bd845 (diff) |
Avoid integer overflow in XGetDeviceProperties() [CVE-2013-1984 7/8]
If the number of items as reported by the Xserver is too large, it
could overflow the calculation for the size of the buffer to copy the
reply into, causing memory corruption.
Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com>
Reviewed-by: Peter Hutterer <peter.hutterer@who-t.net>
Diffstat (limited to 'specs/library.xml')
0 files changed, 0 insertions, 0 deletions