PT-2007-7523 · X.Org+2 · Xorg-X11-Server+3

Sean Larsson

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2007-1003

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE versions (affected versions not specified) SUSE Linux Enterprise versions (affected versions not specified) X.Org X11 server (xserver) versions 7.1-1.1.0 and other versions before 20070403
Description The issue involves multiple vulnerabilities in various packages of openSUSE and SUSE Linux Enterprise operating systems, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, an integer overflow in the ALLOCATE LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server allows remote authenticated users to execute arbitrary code via a large expression, resulting in memory corruption.
Recommendations For openSUSE, update to a version that contains a fix for this vulnerability. For SUSE Linux Enterprise, update to a version that contains a fix for this vulnerability. For X.Org X11 server (xserver), update to a version after 20070403. At the moment, there is no information about a newer version that contains a fix for this vulnerability for some of the affected packages, so it is recommended to monitor the official sources for updates.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04594
BDU:2015-04595
BDU:2015-04596
BDU:2015-04597
BDU:2015-04598
BDU:2015-04599
BDU:2015-04600
BDU:2015-04956
BDU:2015-04957
BDU:2015-04958
BDU:2015-04959
BDU:2015-04960
BDU:2015-04961
CVE-2007-1003
DSA-1294-1
OPENSUSE-SU-2024:11525-1
RHSA-2007:0125
RHSA-2007:0126
RHSA-2007:0127
RHSA-2007_0126
RHSA-2007_0127

Produtos afetados

Red Hat
Suse Linux Enterprise
Xorg-X11-Server
Opensuse