diff options
author | Alan Coopersmith <alan.coopersmith@oracle.com> | 2013-05-04 21:37:49 -0700 |
---|---|---|
committer | Alan Coopersmith <alan.coopersmith@oracle.com> | 2013-05-04 22:26:50 -0700 |
commit | 4254bf0ee4c7a8f9d03841cf0d8e16cbb201dfbd (patch) | |
tree | 558d626eb324144c95b9287373e31cf4e9e7837e /configure.ac | |
parent | 289a1927949e6f278c18d115772e454837702e35 (diff) |
integer overflow in XRRGetProviderProperty() [CVE-2013-1986 4/4]
If the reported number of properties is too large, the calculations
to allocate memory for them may overflow, leaving us returning less
memory to the caller than implied by the value written to *nitems.
(Same as reported against libX11 XGetWindowProperty by Ilja Van Sprundel)
Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com>
Diffstat (limited to 'configure.ac')
0 files changed, 0 insertions, 0 deletions