Test-tool crash via combine_inner divide by zero
Published Jul 17, 2023 · Updated Oct 30, 2024
Divide-by-zero in pixman stress-test commit e4c878 allows attackers to crash the test tool by supplying crafted test data. combine_inner in pixman-combine-float.c performs a floating-point operation that divides by zero, raising an exception. The stress-test binary is confined to the test suite and is not distributed by Ubuntu; Debian assesses the crash as having no security impact.
Summary
What happened
Divide-by-zero in pixman stress-test commit e4c878 allows attackers to crash the test tool by supplying crafted test data. combine_inner in pixman-combine-float.c performs a floating-point operation that divides by zero, raising an exception. The stress-test binary is confined to the test suite and is not distributed by Ubuntu; Debian assesses the crash as having no security impact.
The record
- CVE
- CVE-2023-37769
- Published
- Jul 17, 2023
- Updated
- Oct 30, 2024
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-369
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jul 17, 2023CVE publishedPublication date reported by the CVE source.
- Oct 30, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Pixman issue 76 crash reproducerproof of concept · unverified
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo