PT-2007-7515 · Xfree86+3 · Xfree86-Sdk+28

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2008-1377

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86-twm versions 4.1.0 through 4.3.0 XFree86-sdk versions 4.1.0 through 4.3.0 XFree86-doc versions 4.1.0 through 4.3.0 XFree86-devel versions 4.1.0 through 4.3.0 XFree86-font-utils version 4.3.0 XFree86-xf86cfg versions 4.1.0 XFree86-libs versions 4.1.0 through 4.3.0 XFree86-tools versions 4.1.0 through 4.3.0 XFree86-xdm versions 4.1.0 through 4.3.0 XFree86-xfs versions 4.1.0 through 4.3.0 XFree86-Xvfb versions 4.1.0 through 4.3.0 XFree86-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-2-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-14-75dpi-fonts version 4.3.0 XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-9-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-14-100dpi-fonts version 4.3.0 XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.3.0 xorg-x11-server versions prior to 1.3.0.0-r6 xorg-x11-server-Xorg version 1.1.1 xorg-x11-server-Xvfb version 1.1.1 xorg-x11-server-Xnest version 1.1.1 xorg-x11-server-Xdmx version 1.1.1 xorg-x11-server-Xephyr version 1.1.1
Description The issue allows context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption. The SProcRecordCreateContext and SProcRecordRegisterClients functions in the Record extension and the SProcSecurityGenerateAuthorization function in the Security extension in the X server are affected. Exploitation of the vulnerabilities can be done remotely.
Recommendations For XFree86-twm versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-sdk versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-doc versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-devel versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-font-utils version 4.3.0, update to a version outside this range. For XFree86-xf86cfg versions 4.1.0, update to a version outside this range. For XFree86-libs versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-tools versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-xdm versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-xfs versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-Xvfb versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-ISO8859-2-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-ISO8859-14-75dpi-fonts version 4.3.0, update to a version outside this range. For XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-ISO8859-9-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For XFree86-ISO8859-14-100dpi-fonts version 4.3.0, update to a version outside this range. For XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside this range. For xorg-x11-server versions prior to 1.3.0.0-r6, update to version 1.3.0.0-r6 or later. For xorg-x11-server-Xorg version 1.1.1, update to a version outside this range. For xorg-x11-server-Xvfb version 1.1.1, update to a version outside this range. For xorg-x11-server-Xnest version 1.1.1, update to a version outside this range. For xorg-x11-server-Xdmx version 1.1.1, update to a version outside this range. For xorg-x11-server-Xephyr version 1.1.1, update to a version outside this range.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04179
BDU:2015-04180
BDU:2015-04181
BDU:2015-04182
BDU:2015-06578
BDU:2015-06588
BDU:2015-06589
BDU:2015-06591
BDU:2015-06594
BDU:2015-06597
BDU:2015-06600
BDU:2015-06603
BDU:2015-06608
BDU:2015-06609
BDU:2015-06610
BDU:2015-06611
BDU:2015-06612
BDU:2015-06613
BDU:2015-06614
BDU:2015-06615
BDU:2015-06616
BDU:2015-06617
BDU:2015-06618
BDU:2015-06619
BDU:2015-06620
BDU:2015-06621
BDU:2015-06622
BDU:2015-06623
BDU:2015-06624
BDU:2015-06625
BDU:2015-06626
BDU:2015-06627
BDU:2015-06628
BDU:2015-06629
BDU:2015-06630
BDU:2015-06631
BDU:2015-06632
BDU:2015-06633
BDU:2015-06634
BDU:2015-06635
BDU:2015-06636
BDU:2015-06637
BDU:2015-06638
BDU:2015-06639
BDU:2015-06640
BDU:2015-06641
BDU:2015-06642
BDU:2015-06643
BDU:2015-06644
BDU:2015-06645
BDU:2015-06646
BDU:2015-06647
BDU:2015-06648
BDU:2015-06649
BDU:2015-06650
BDU:2015-06651
BDU:2015-06652
BDU:2015-06653
BDU:2015-06654
BDU:2015-06655
BDU:2015-06656
BDU:2015-06657
BDU:2015-08386
BDU:2015-08387
BDU:2015-08388
BDU:2015-08389
BDU:2015-08390
BDU:2015-08391
BDU:2015-08392
BDU:2015-08393
BDU:2015-08394
BDU:2015-08395
BDU:2015-08396
BDU:2015-08397
BDU:2015-08398
BDU:2015-08399
BDU:2015-08400
BDU:2015-08401
BDU:2015-08402
BDU:2015-08403
BDU:2015-08404
BDU:2015-08405
BDU:2015-09631
CVE-2008-1377
DSA-1595-1
DTSA-141-1
HPSBUX02381
OPENSUSE-SU-2024:11525-1
RHSA-2008:0502
RHSA-2008:0503
RHSA-2008:0504
RHSA-2008:0512
RHSA-2008_0503
RHSA-2008_0504

Affected Products

Hp-Ux
Red Hat
Xfree86-100Dpi-Fonts
Xfree86-75Dpi-Fonts
Xfree86-Iso8859-14-100Dpi-Fonts
Xfree86-Iso8859-14-75Dpi-Fonts
Xfree86-Iso8859-15-100Dpi-Fonts
Xfree86-Iso8859-15-75Dpi-Fonts
Xfree86-Iso8859-2-100Dpi-Fonts
Xfree86-Iso8859-2-75Dpi-Fonts
Xfree86-Iso8859-9-100Dpi-Fonts
Xfree86-Iso8859-9-75Dpi-Fonts
Xfree86-Xvfb
Xfree86-Devel
Xfree86-Doc
Xfree86-Font-Utils
Xfree86-Libs
Xfree86-Sdk
Xfree86-Tools
Xfree86-Twm
Xfree86-Xdm
Xfree86-Xf86Cfg
Xfree86-Xfs
Xorg-X11-Server
Xorg-X11-Server-Xdmx
Xorg-X11-Server-Xephyr
Xorg-X11-Server-Xnest
Xorg-X11-Server-Xorg
Xorg-X11-Server-Xvfb