PT-2011-1118 · Xorg+2 · Xorg-X11-Server-Xvfb+9

Published

2011-10-06

·

Updated

2012-09-13

·

CVE-2010-4819

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions xorg-x11-server-Xorg versions 1.7.7 xorg-x11-server-Xephyr versions 1.7.7 xorg-x11-server-common versions 1.7.7 xorg-x11-server-debuginfo versions 1.7.7 xorg-x11-server-Xnest versions 1.7.7 xorg-x11-server-Xdmx versions 1.7.7 xorg-x11-server-devel versions 1.7.7 xorg-x11-server-Xvfb versions 1.7.7
Description The issue concerns multiple vulnerabilities in the xorg-x11-server package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely by an attacker who has passed the authentication procedure. The ProcRenderAddGlyphs function in the Render extension allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
Recommendations For xorg-x11-server-Xorg version 1.7.7, update to a newer version to mitigate the risk. For xorg-x11-server-Xephyr version 1.7.7, update to a newer version to mitigate the risk. For xorg-x11-server-common version 1.7.7, update to a newer version to mitigate the risk. For xorg-x11-server-debuginfo version 1.7.7, update to a newer version to mitigate the risk. For xorg-x11-server-Xnest version 1.7.7, update to a newer version to mitigate the risk. For xorg-x11-server-Xdmx version 1.7.7, update to a newer version to mitigate the risk. For xorg-x11-server-devel version 1.7.7, update to a newer version to mitigate the risk. For xorg-x11-server-Xvfb version 1.7.7, update to a newer version to mitigate the risk. As a temporary workaround, consider disabling the ProcRenderAddGlyphs function until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06580
BDU:2015-06582
BDU:2015-06585
BDU:2015-06587
BDU:2015-06593
BDU:2015-06596
BDU:2015-06599
BDU:2015-06602
BDU:2015-06605
BDU:2015-08660
BDU:2015-08661
BDU:2015-08662
BDU:2015-08663
BDU:2015-08664
BDU:2015-08665
BDU:2015-08666
BDU:2015-08667
BDU:2015-08668
CVE-2010-4819
RHSA-2011:1359
RHSA-2011:1360
RHSA-2011_1359
RHSA-2011_1360

Affected Products

Red Hat
Suse
Xorg-X11-Server-Xdmx
Xorg-X11-Server-Xephyr
Xorg-X11-Server-Xnest
Xorg-X11-Server-Xorg
Xorg-X11-Server-Xvfb
Xorg-X11-Server-Common
Xorg-X11-Server-Debuginfo
Xorg-X11-Server-Devel