summaryrefslogtreecommitdiff
path: root/src/XSetMode.c
diff options
context:
space:
mode:
authorAlan Coopersmith <alan.coopersmith@oracle.com>2013-04-26 22:48:36 -0700
committerAlan Coopersmith <alan.coopersmith@oracle.com>2013-05-23 08:13:25 -0700
commit5398ac0797f7516f2c9b8f2869a6c6d071437352 (patch)
tree90de15a85537cf5c85704a3a6dd42ba5bb90c203 /src/XSetMode.c
parent91434737f592e8f5cc1762383882a582b55fc03a (diff)
unvalidated lengths in XQueryDeviceState() [CVE-2013-1998 3/3]
If the lengths given for each class state in the reply add up to more than the rep.length, we could read past the end of the buffer allocated to hold the data read from the server. Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com> Reviewed-by: Peter Hutterer <peter.hutterer@who-t.net>
Diffstat (limited to 'src/XSetMode.c')
0 files changed, 0 insertions, 0 deletions