PT-2003-2523 · Debian+1 · Xlibosmesa3+5
Published
1970-01-01
·
Updated
2017-10-10
·
CVE-2004-0093
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
xlibosmesa3-dbg (affected versions not specified)
xlib6g-dev (affected versions not specified)
xfonts-pex (affected versions not specified)
xlibosmesa3 (affected versions not specified)
xlib6g (affected versions not specified)
XFree86 version 4.1.0
Description
The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including xlibosmesa3-dbg, xlib6g-dev, xfonts-pex, xlibosmesa3, and xlib6g. These vulnerabilities can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information. In the case of XFree86 4.1.0, the vulnerability allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).
Recommendations
For xlibosmesa3-dbg, consider updating to a newer version or applying available patches to resolve the issue.
For xlib6g-dev, consider updating to a newer version or applying available patches to resolve the issue.
For xfonts-pex, consider updating to a newer version or applying available patches to resolve the issue.
For xlibosmesa3, consider updating to a newer version or applying available patches to resolve the issue.
For xlib6g, consider updating to a newer version or applying available patches to resolve the issue.
For XFree86 version 4.1.0, consider updating to a newer version to address the out-of-bounds array index issue in the GLX extension and DRI.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xfree86
Xfonts-Pex
Xlib6G
Xlib6G-Dev
Xlibosmesa3
Xlibosmesa3-Dbg