An integer underflow vulnerability in Pixman may allow a context-dependent attacker to cause Denial of Service.
| Package | x11-libs/pixman on all architectures | 
|---|---|
| Affected versions | < 0.32.4 | 
| Unaffected versions | >= 0.32.4 | 
Pixman is a pixel manipulation library.
The trapezoid handling code in Pixman contains an integer underflow vulnerability.
A context-dependent attacker could entice a user to open a specially crafted file using an application linked against Pixman, possibly resulting in execution of arbitrary code with the privileges of the process, or a Denial of Service condition.
There is no known workaround at this time.
All Pixman users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=x11-libs/pixman-0.32.4"
Packages which depend on this library may need to be recompiled. Tools such as revdep-rebuild may assist in identifying these packages.
      Release date
      
      February 02, 2014
    
      Latest revision
      
      February 02, 2014: 1
    
      Severity
      
      normal
    
      Exploitable
      
      local, remote
    
Bugzilla entries