Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 24 Feb 2016 10:26:40 -0800
From: Alan Coopersmith <>
CC: "X.Org Security Team" <>
Subject: Re: [Pixman] create_bits(): Cast the result of height
 * stride to size_t

On 02/24/16 04:10 AM, Gustavo Grieco wrote:
>   Hi,
> There is an (old) integer overflow in create_bits in the pixman library.
> Patch and details are available here:

The quoted patch was applied to the master branch of the pixman git repo as:

and to the pixman-0.32 branch as:

It is included in pixman 0.32.6 and later releases.

	-Alan Coopersmith-    
	 Oracle Solaris Engineering -

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.