PT-2006-1084 · X.Org+2 · Xorg-Server+3
Publicado
2006-12-31
·
Atualizado
2024-06-15
·
CVE-2006-6101
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
xorg-server versions prior to 1.1.1-r4
X.Org versions 6.8.2, 6.9.0, 7.0, and 7.1
Description:
The issue is related to multiple vulnerabilities in the xorg-server package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, an integer overflow in the
ProcRenderAddGlyphs function in the Render extension for X.Org can allow local users to execute arbitrary code via a crafted X protocol request, triggering memory corruption during the processing of glyph management data structures.Recommendations:
For xorg-server versions prior to 1.1.1-r4, update to version 1.1.1-r4 or later.
For X.Org versions 6.8.2, 6.9.0, 7.0, and 7.1, consider disabling the Render extension until a patch is available.
As a temporary workaround, restrict access to the
ProcRenderAddGlyphs function to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hp-Ux
Red Hat
X.Org
Xorg-Server