Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xf86-video-openchrome. | Aug 30, 2017 | Jun 15, 2013 |
| Debian | — | Upgrade xserver-xorg-video-openchrome | Jul 30, 2024 | Jun 15, 2013 |
| Freebsd | — | Upgrade xf86-video-openchromeUpgrade libXvMCUpgrade libXtstUpgrade libXcursorUpgrade libXfixesUpgrade libGLUpgrade libXineramaUpgrade libXrenderUpgrade libFSUpgrade libXtUpgrade libXxf86vmUpgrade libXiUpgrade libXpUpgrade libXextUpgrade libX11Upgrade libXrandrUpgrade libXvUpgrade libXresUpgrade libXxf86dgaUpgrade libdmxUpgrade libxcb | Dec 10, 2025 | Jun 4, 2013 |
| Gentoo Linux | — | Upgrade x11-base/xorg-server. | Oct 30, 2017 | Jun 15, 2013 |
| Ubuntu | — | Upgrade xserver-xorg-video-openchrome-lts-quantalUpgrade xserver-xorg-video-openchrome | Nov 8, 2024 | Jun 15, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub