PT-2014-1853 · X.Org+5 · Xorg-X11-Server+5

Ilja Van Sprundel

·

Published

2014-12-09

·

Updated

2025-08-29

·

CVE-2014-8094

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xorg-x11-server versions 1.7.0 through 1.16.x before 1.16.3 xorg-x11-server-Xdmx version 1.15.0 xorg-x11-server-debuginfo version 1.15.0 xorg-x11-server-Xephyr version 1.15.0 xorg-x11-server-source version 1.15.0 xorg-x11-server-Xnest version 1.15.0 xorg-x11-server-Xvfb version 1.15.0 xorg-x11-server-common version 1.15.0 xorg-x11-server-devel version 1.15.0
Description The issue is related to multiple vulnerabilities in the xorg-x11-server package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely by an authenticated attacker. Specifically, an integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via a crafted request, triggering an out-of-bounds read or write.
Recommendations For xorg-x11-server versions 1.7.0 through 1.16.x before 1.16.3, update to version 1.16.3 or later to resolve the issue. For xorg-x11-server-Xdmx version 1.15.0, consider disabling the vulnerable component until a patch is available. For xorg-x11-server-debuginfo version 1.15.0, restrict access to the vulnerable module to minimize the risk of exploitation. For xorg-x11-server-Xephyr version 1.15.0, avoid using the vulnerable function until the issue is resolved. For xorg-x11-server-source version 1.15.0, xorg-x11-server-Xnest version 1.15.0, xorg-x11-server-Xvfb version 1.15.0, xorg-x11-server-common version 1.15.0, and xorg-x11-server-devel version 1.15.0, update to a newer version that contains a fix for this issue, if available. At the moment, there is no information about a newer version that contains a fix for xorg-x11-server-1.15.0 and xorg-x11-server-Xorg-1.15.0.

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1154
BDU:2015-06579
BDU:2015-06581
BDU:2015-06584
BDU:2015-06586
BDU:2015-06590
BDU:2015-06592
BDU:2015-06595
BDU:2015-06598
BDU:2015-06601
BDU:2015-06604
BDU:2015-09275
BDU:2015-09276
BDU:2015-09277
BDU:2015-09278
BDU:2015-09279
BDU:2015-09280
BDU:2015-09281
BDU:2015-09282
BDU:2015-09283
BDU:2015-09284
CESA-2014_1983
CVE-2014-8094
DLA-120-1
DSA-3095-1
MGASA-2014-0532
RHSA-2014:1983
RHSA-2014_1983
SUSE-SU-2015:0427-1
SUSE-SU-2015:1025-1
USN-2436-1
USN-2436-2

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Xorg-X11-Server