PT-2003-2524 · Debian+1 · Xlibosmesa3+6

Published

1970-01-01

·

Updated

2017-10-10

·

CVE-2004-0094

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86 version 4.1.0 xlibosmesa3-dbg (affected versions not specified) xlib6g-dev (affected versions not specified) xfonts-pex (affected versions not specified) xlibosmesa3 (affected versions not specified) xlib6g (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including xlibosmesa3-dbg, xlib6g-dev, xfonts-pex, xlibosmesa3, and xlib6g. These vulnerabilities can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information. Specifically, integer signedness errors in XFree86 4.1.0 can allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).
Recommendations For XFree86 version 4.1.0, consider upgrading to a newer version to mitigate the risk. For xlibosmesa3-dbg, xlib6g-dev, xfonts-pex, xlibosmesa3, and xlib6g, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01798
BDU:2015-01799
BDU:2015-01800
BDU:2015-01801
BDU:2015-01802
CVE-2004-0094
DSA-443

Affected Products

Debian
Xfree86
Xfonts-Pex
Xlib6G
Xlib6G-Dev
Xlibosmesa3
Xlibosmesa3-Dbg