Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.
http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
http://www.ubuntu.com/usn/USN-1871-1