PT-2006-1085 · X.Org+2 · Xorg-Server+3

Publicado

2006-12-31

·

Atualizado

2024-06-15

·

CVE-2006-6102

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: xorg-server versions prior to 1.1.1-r4 X.Org versions 6.8.2, 6.9.0, 7.0, and 7.1
Description: The issue is related to multiple vulnerabilities in the xorg-server package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, an integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org allows local users to execute arbitrary code via a crafted X protocol request, triggering memory corruption during processing of unspecified data structures.
Recommendations: For xorg-server versions prior to 1.1.1-r4, update to version 1.1.1-r4 or later. For X.Org versions 6.8.2, 6.9.0, 7.0, and 7.1, consider disabling the DBE extension until a patch is available. As a temporary workaround, restrict access to the ProcDbeGetVisualInfo function to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09544
CVE-2006-6102
DSA-1249-1
HPSBUX02225
OPENSUSE-SU-2024:11525-1
RHSA-2007:0002
RHSA-2007:0003
RHSA-2007_0003

Produtos afetados

Hp-Ux
Red Hat
X.Org
Xorg-Server