CVE-2013-1994

Publication date 23 May 2013

Last updated 24 July 2024


Ubuntu priority

Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.

Status

Package Ubuntu Release Status
xserver-xorg-video-openchrome 13.04 raring
Fixed 1:0.3.1-0ubuntu1.13.04.1
12.10 quantal
Fixed 1:0.3.1-0ubuntu1.12.10.1
12.04 LTS precise
Fixed 1:0.2.904+svn1050-1ubuntu0.1
10.04 LTS lucid Ignored end of life
xserver-xorg-video-openchrome-lts-quantal 13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise
Fixed 1:0.3.1-0ubuntu1~precise3
10.04 LTS lucid Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
xserver-xorg-video-openchrome

References

Related Ubuntu Security Notices (USN)

    • USN-1871-1
    • xserver-xorg-video-openchrome vulnerability
    • 10 June 2013

Other references