PT-2007-7522 · X.Org+3 · Libx11+5

Published

1970-01-01

·

Updated

2024-06-26

·

CVE-2007-1667

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE versions (affected versions not specified) SUSE Linux Enterprise versions (affected versions not specified) Gentoo Linux libX11 versions prior to 1.0.3-r2 X.Org libx11 versions prior to 1.0.3
Description The issue involves multiple vulnerabilities in various packages of openSUSE and SUSE Linux Enterprise operating systems, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are related to integer overflows in the XGetPixel function in ImUtil.c in X.Org libx11 and the XInitImage function in xwd.c for ImageMagick, allowing user-assisted remote attackers to cause a denial of service or obtain sensitive information via crafted images.
Recommendations For openSUSE, update the affected packages to the latest version. For SUSE Linux Enterprise, update the affected packages to the latest version. For Gentoo Linux libX11, update to version 1.0.3-r2 or later. For X.Org libx11, update to version 1.0.3 or later. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04594
BDU:2015-04595
BDU:2015-04596
BDU:2015-04597
BDU:2015-04598
BDU:2015-04599
BDU:2015-04600
BDU:2015-04956
BDU:2015-04957
BDU:2015-04958
BDU:2015-04959
BDU:2015-04960
BDU:2015-04961
BDU:2015-09563
CVE-2007-1667
DSA-1294-1
DSA-1858-1
DSA-1903-1
RHSA-2007:0125
RHSA-2007:0126
RHSA-2007:0157
RHSA-2007_0126
RHSA-2007_0157

Affected Products

Imagemagick
Red Hat
Suse Linux Enterprise
X.Org Libx11
Libx11
Opensuse