Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8094

Опубликовано: 09 дек. 2014
Источник: redhat
CVSS2: 2.3

Описание

Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.

An integer overflow flaw was found in the way the X.Org server calculated memory requirements for certain DRI2 extension requests. A malicious, authenticated client could use this flaw to crash the X.Org server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xorg-x11-serverNot affected
Red Hat Enterprise Linux 6xorg-x11-serverFixedRHSA-2014:198311.12.2014
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2014:198311.12.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1168691xorg-x11-server: integer overflow in DRI2 extension function ProcDRI2GetBuffers()

2.3 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.

nvd
больше 10 лет назад

Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.

debian
больше 10 лет назад

Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extens ...

github
больше 3 лет назад

Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.

oracle-oval
больше 10 лет назад

ELSA-2014-1983: xorg-x11-server security update (IMPORTANT)

2.3 Low

CVSS2