Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultant from an integer overflow in the fast_composite_scaled_bilinear function in pixman-inlines.h, which triggers an infinite loop.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade pixmanUpgrade pixman-devel | Dec 1, 2016 | Jan 31, 2013 |
| Debian | — | Upgrade pixman | Jul 30, 2024 | Jan 31, 2013 |
| Oracle_linux | — | Upgrade pixmanUpgrade pixman-devel | Oct 16, 2024 | Jan 31, 2013 |
| Suse | — | Upgrade libpixman-1-0-32bitUpgrade libpixman-1-0Upgrade libpixman-1-0-x86Upgrade sle-sdk-releaseUpgrade libpixman-1-0-develUpgrade pixman | Dec 12, 2013 | Jan 31, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub