PT-2007-7516 · Xfree86+3 · Xfree86-Mesa-Libgl+35
Daniel Stone
+1
·
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2008-1379
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
XFree86-twm versions 4.1.0 through 4.3.0
XFree86-100dpi-fonts versions 4.1.0 through 4.3.0
XFree86-sdk version 4.3.0
XFree86-doc versions 4.1.0 through 4.3.0
XFree86-devel versions 4.1.0 through 4.3.0
XFree86-font-utils version 4.3.0
XFree86-xf86cfg versions 4.1.0
XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.3.0
XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.3.0
XFree86-cyrillic-fonts versions 4.1.0 through 4.3.0
xorg-x11-server-sdk version 1.1.1
xorg-x11-server-Xnest version 1.1.1
xorg-x11-server-Xdmx version 1.1.1
xorg-x11-server-Xorg version 1.1.1
xorg-x11-server version 1.1.1
xorg-x11-server-Xvfb version 1.1.1
xorg-x11-server-Xephyr version 1.1.1
xorg-x11-server-randr-source version 1.1.1
XFree86-75dpi-fonts versions 4.1.0 through 4.3.0
XFree86-Mesa-libGL version 4.3.0
XFree86-libs versions 4.1.0 through 4.3.0
XFree86-libs-data version 4.3.0
XFree86-xdm versions 4.1.0 through 4.3.0
XFree86-xfs versions 4.1.0 through 4.3.0
XFree86-Xvfb versions 4.1.0 through 4.3.0
XFree86-truetype-fonts version 4.3.0
XFree86-base-fonts version 4.3.0
XFree86-syriac-fonts version 4.3.0
XFree86-ISO8859-14-75dpi-fonts version 4.3.0
XFree86-ISO8859-2-75dpi-fonts versions 4.1.0 through 4.3.0
XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.3.0
XFree86-ISO8859-9-100dpi-fonts versions 4.1.0 through 4.3.0
XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.3.0
XFree86-tools versions 4.1.0 through 4.3.0
Description
The issue is related to multiple vulnerabilities in various XFree86 and xorg-x11-server packages, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities exist in the MIT-SHM extension in the X server, allowing context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.
Recommendations
For XFree86-twm versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-sdk version 4.3.0, update to a version outside of this range.
For XFree86-doc versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-devel versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-font-utils version 4.3.0, update to a version outside of this range.
For XFree86-xf86cfg versions 4.1.0, update to a version outside of this range.
For XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-cyrillic-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For xorg-x11-server-sdk version 1.1.1, update to a version outside of this range.
For xorg-x11-server-Xnest version 1.1.1, update to a version outside of this range.
For xorg-x11-server-Xdmx version 1.1.1, update to a version outside of this range.
For xorg-x11-server-Xorg version 1.1.1, update to a version outside of this range.
For xorg-x11-server version 1.1.1, update to a version outside of this range.
For xorg-x11-server-Xvfb version 1.1.1, update to a version outside of this range.
For xorg-x11-server-Xephyr version 1.1.1, update to a version outside of this range.
For xorg-x11-server-randr-source version 1.1.1, update to a version outside of this range.
For XFree86-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-Mesa-libGL version 4.3.0, update to a version outside of this range.
For XFree86-libs versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-libs-data version 4.3.0, update to a version outside of this range.
For XFree86-xdm versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-xfs versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-Xvfb versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-truetype-fonts version 4.3.0, update to a version outside of this range.
For XFree86-base-fonts version 4.3.0, update to a version outside of this range.
For XFree86-syriac-fonts version 4.3.0, update to a version outside of this range.
For XFree86-ISO8859-14-75dpi-fonts version 4.3.0, update to a version outside of this range.
For XFree86-ISO8859-2-75dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-ISO8859-9-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.3.0, update to a version outside of this range.
For XFree86-tools versions 4.1.0 through 4.3.0, update to a version outside of this range.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux
Red Hat
Xfree86-100Dpi-Fonts
Xfree86-75Dpi-Fonts
Xfree86-Iso8859-14-75Dpi-Fonts
Xfree86-Iso8859-15-100Dpi-Fonts
Xfree86-Iso8859-15-75Dpi-Fonts
Xfree86-Iso8859-2-100Dpi-Fonts
Xfree86-Iso8859-2-75Dpi-Fonts
Xfree86-Iso8859-9-100Dpi-Fonts
Xfree86-Iso8859-9-75Dpi-Fonts
Xfree86-Mesa-Libgl
Xfree86-Xvfb
Xfree86-Base-Fonts
Xfree86-Cyrillic-Fonts
Xfree86-Devel
Xfree86-Doc
Xfree86-Font-Utils
Xfree86-Libs
Xfree86-Libs-Data
Xfree86-Sdk
Xfree86-Syriac-Fonts
Xfree86-Tools
Xfree86-Truetype-Fonts
Xfree86-Twm
Xfree86-Xdm
Xfree86-Xf86Cfg
Xfree86-Xfs
Xorg-X11-Server
Xorg-X11-Server-Xdmx
Xorg-X11-Server-Xephyr
Xorg-X11-Server-Xnest
Xorg-X11-Server-Xorg
Xorg-X11-Server-Xvfb
Xorg-X11-Server-Randr-Source
Xorg-X11-Server-Sdk