PT-2007-7517 · Xfree86+2 · Xfree86+3

Daniel Stone

+1

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2008-2360

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86-doc versions 4.1.0 through 4.3.0 XFree86-twm versions 4.1.0 through 4.3.0 XFree86-Mesa-libGLU version 4.3.0 XFree86-devel versions 4.1.0 through 4.3.0 XFree86-font-utils version 4.3.0 XFree86-xf86cfg versions 4.1.0 XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-cyrillic-fonts versions 4.1.0 through 4.3.0 xorg-x11-server-sdk version 1.1.1 XFree86-ISO8859-14-75dpi-fonts version 4.3.0 XFree86-ISO8859-9-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-xdm versions 4.1.0 through 4.3.0 XFree86-libs versions 4.1.0 through 4.3.0 XFree86-tools versions 4.1.0 through 4.3.0 XFree86-ISO8859-2-75dpi-fonts versions 4.1.0 through 4.3.0 xorg-server versions prior to 1.3.0.0-r6 XFree86-syriac-fonts version 4.3.0 xorg-x11-server-Xdmx version 1.1.1 XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.3.0 xorg-x11-server-Xnest version 1.1.1 XFree86-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-base-fonts version 4.3.0 XFree86-ISO8859-15-100dpi-fonts version 4.1.0 xorg-x11-server-Xorg version 1.1.1 xorg-x11-server version 1.1.1 xorg-x11-server-Xephyr version 1.1.1 XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-devel version 4.1.0 xorg-x11-Xvnc XFree86-ISO8859-9-100dpi-fonts version 4.1.0 XFree86-xfs versions 4.1.0 through 4.3.0 XFree86-Xvfb versions 4.1.0 through 4.3.0 xorg-x11-server-randr-source version 1.1.1 XFree86-4.1.0 XFree86-4.3.0 XFree86-ISO8859-2-75dpi-fonts version 4.3.0 XFree86-libs-data version 4.3.0 XFree86-ISO8859-14-100dpi-fonts version 4.3.0 XFree86-ISO8859-9-75dpi-fonts version 4.1.0 XFree86-Xnest versions 4.1.0 through 4.3.0 XFree86-sdk version 4.3.0 XFree86-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-Mesa-libGL version 4.3.0 XFree86-ISO8859-2-100dpi-fonts version 4.1.0 XFree86-truetype-fonts version 4.3.0
Description The issue is related to multiple vulnerabilities in various XFree86 and xorg-x11 packages, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are caused by an integer overflow in the AllocateGlyph function in the Render extension in the X server, allowing context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, triggering a heap-based buffer overflow.
Recommendations For XFree86-doc versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-twm versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-Mesa-libGLU version 4.3.0, update to a version outside of this range. For XFree86-devel versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-font-utils version 4.3.0, update to a version outside of this range. For XFree86-xf86cfg versions 4.1.0, update to a version outside of this range. For XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-cyrillic-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For xorg-x11-server-sdk version 1.1.1, update to a version outside of this range. For XFree86-ISO8859-14-75dpi-fonts version 4.3.0, update to a version outside of this range. For XFree86-ISO8859-9-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-xdm versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-libs versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-tools versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-ISO8859-2-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For xorg-server versions prior to 1.3.0.0-r6, update to version 1.3.0.0-r6 or later. For XFree86-syriac-fonts version 4.3.0, update to a version outside of this range. For xorg-x11-server-Xdmx version 1.1.1, update to a version outside of this range. For XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For xorg-x11-server-Xnest version 1.1.1, update to a version outside of this range. For XFree86-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-base-fonts version 4.3.0, update to a version outside of this range. For XFree86-ISO8859-15-100dpi-fonts version 4.1.0, update to a version outside of this range. For xorg-x11-server-Xorg version 1.1.1, update to a version outside of this range. For xorg-x11-server version 1.1.1, update to a version outside of this range. For xorg-x11-server-Xephyr version 1.1.1, update to a version outside of this range. For XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-devel version 4.1.0, update to a version outside of this range. For xorg-x11-Xvnc, update to a version outside of this range. For XFree86-ISO8859-9-100dpi-fonts version 4.1.0, update to a version outside of this range. For XFree86-xfs versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-Xvfb versions 4.1.0 through 4.3.0, update to a version outside of this range. For xorg-x11-server-randr-source version 1.1.1, update to a version outside of this range. For XFree86-4.1.0, update to a version outside of this range. For XFree86-4.3.0, update to a version outside of this range. For XFree86-ISO8859-2-75dpi-fonts version 4.3.0, update to a version outside of this range. For XFree86-libs-data version 4.3.0, update to a version outside of this range. For XFree86-ISO8859-14-100dpi-fonts version 4.3.0, update to a version outside of this range. For XFree86-ISO8859-9-75dpi-fonts version 4.1.0, update to a version outside of this range. For XFree86-Xnest versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-sdk version 4.3.0, update to a version outside of this range. For XFree86-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range. For XFree86-Mesa-libGL version 4.3.0, update to a version outside of this range. For XFree86-ISO8859-2-100dpi-fonts version 4.1.0, update to a version outside of this range. For XFree86-truetype-fonts version 4.3.0, update to a version outside of this range.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04179
BDU:2015-04180
BDU:2015-04181
BDU:2015-04182
BDU:2015-06578
BDU:2015-06588
BDU:2015-06589
BDU:2015-06591
BDU:2015-06594
BDU:2015-06597
BDU:2015-06600
BDU:2015-06603
BDU:2015-06608
BDU:2015-06609
BDU:2015-06610
BDU:2015-06611
BDU:2015-06612
BDU:2015-06613
BDU:2015-06614
BDU:2015-06615
BDU:2015-06616
BDU:2015-06617
BDU:2015-06618
BDU:2015-06619
BDU:2015-06620
BDU:2015-06621
BDU:2015-06622
BDU:2015-06623
BDU:2015-06624
BDU:2015-06625
BDU:2015-06626
BDU:2015-06627
BDU:2015-06628
BDU:2015-06629
BDU:2015-06630
BDU:2015-06631
BDU:2015-06632
BDU:2015-06633
BDU:2015-06634
BDU:2015-06635
BDU:2015-06636
BDU:2015-06637
BDU:2015-06638
BDU:2015-06639
BDU:2015-06640
BDU:2015-06641
BDU:2015-06642
BDU:2015-06643
BDU:2015-06644
BDU:2015-06645
BDU:2015-06646
BDU:2015-06647
BDU:2015-06648
BDU:2015-06649
BDU:2015-06650
BDU:2015-06651
BDU:2015-06652
BDU:2015-06653
BDU:2015-06654
BDU:2015-06655
BDU:2015-06656
BDU:2015-06657
BDU:2015-08386
BDU:2015-08387
BDU:2015-08388
BDU:2015-08389
BDU:2015-08390
BDU:2015-08391
BDU:2015-08392
BDU:2015-08393
BDU:2015-08394
BDU:2015-08395
BDU:2015-08396
BDU:2015-08397
BDU:2015-08398
BDU:2015-08399
BDU:2015-08400
BDU:2015-08401
BDU:2015-08402
BDU:2015-08403
BDU:2015-08404
BDU:2015-08405
BDU:2015-09631
CVE-2008-2360
DSA-1595-1
DTSA-141-1
OPENSUSE-SU-2024:11525-1
RHSA-2008:0502
RHSA-2008:0503
RHSA-2008:0504
RHSA-2008:0512
RHSA-2008_0503
RHSA-2008_0504

Produtos afetados

Red Hat
Xfree86
Xorg-X11-Xvnc
Xorg-X11-Server