CVE Vulnerabilities

CVE-2008-1377

Published: Jun 16, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.

Affected Software

Name Vendor Start Version End Version
X11 X r7.3 (including) r7.3 (including)
Red Hat Enterprise Linux 2.1 RedHat XFree86-0:4.1.0-88.EL *
Red Hat Enterprise Linux 3 RedHat XFree86-0:4.3.0-128.EL *
Red Hat Enterprise Linux 4 RedHat xorg-x11-0:6.8.2-1.EL.33.0.4 *
Red Hat Enterprise Linux 5 RedHat xorg-x11-server-0:1.1.1-48.41.el5_2.1 *
Xorg-server Ubuntu dapper *
Xorg-server Ubuntu devel *
Xorg-server Ubuntu feisty *
Xorg-server Ubuntu gutsy *
Xorg-server Ubuntu hardy *
Xorg-server Ubuntu upstream *

References