PublicDateAtUSN: 2015-12-31
Candidate: CVE-2015-5297
PublicDate: 2019-07-31 23:15:00 UTC
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5297
 https://ubuntu.com/security/notices/USN-3843-1
 https://ubuntu.com/security/notices/USN-3843-2
Description:
 An integer overflow issue has been reported in the general_composite_rect()
 function in pixman prior to version 0.32.8. An attacker could exploit this
 issue to cause an application using pixman to crash or, potentially,
 execute arbitrary code.
Ubuntu-Description:
Notes:
Bugs:
 https://bugs.freedesktop.org/show_bug.cgi?id=92027
Priority: medium
Discovered-by:
Assigned-to: mdeslaur
CVSS:
 nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL]


Patches_pixman:
 upstream: https://cgit.freedesktop.org/pixman/commit/?id=f10b5449a8b22a26839c58a716b74d6b7a8bcb80 (bp)
 upstream: https://cgit.freedesktop.org/pixman/commit/?id=15aa37adeca79a22b393ff451e6d29f484c3b0ef (bp)
 upstream: https://cgit.freedesktop.org/pixman/commit/?id=8b49d4b6b460d0c9299bca4ccddd7cd00d8f8441
 upstream: https://cgit.freedesktop.org/pixman/commit/?id=23525b4ea5bc2dd67f8f65b90d023b6580ecbc36
upstream_pixman: released (0.33.4-1)
precise/esm_pixman: released (0.30.2-1ubuntu0.0.0.0.4)
trusty_pixman: released (0.30.2-2ubuntu1.2)
trusty/esm_pixman: released (0.30.2-2ubuntu1.2)
xenial_pixman: not-affected (0.33.6-1)
esm-infra/xenial_pixman: not-affected (0.33.6-1)
bionic_pixman: not-affected (0.34.0-2)
cosmic_pixman: not-affected
devel_pixman: not-affected
