X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
BID:27353
Info
X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
| Bugtraq ID: | 27353 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6429 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 17 2008 12:00AM |
| Updated: | Apr 16 2015 05:49PM |
| Credit: | regenrecht is credited with the discovery of this vulnerability. |
| Vulnerable: |
X.org Xserver 1.3 X.org xorg-server 1.4 X.org xorg-server 1.3.99.2 (RC2) X.org xorg-server 1.2 X.org xorg-server 1.02-r5 X.org xorg-server 1.0.2-r6 X.org X11R7 1.1.1 X.org X11R7 1.0.2 X.org X11R7 1.0.1 X.org X11R7 1.0 X.org X11R7 7.2 X.org X11R7 7.1 X.org X11R7 7.0 X.org X11R6 6.9 X.org X11R6 6.8.2 X.org X11R6 6.8.1 X.org X11R6 6.8 X.org X11R6 6.7 .0 X.org X11R6 5.1 X.org X11R6 4.0 X.org LibXfont 1.3.1 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux Virtualization 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server OpenBSD OpenBSD 4.3 OpenBSD OpenBSD 4.2 OpenBSD OpenBSD 4.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Linux Terminal Server Project Linux Terminal Server Project 4.2 IBM Aix 7.1.1 IBM Aix 7.1 IBM Aix 6.1.7 IBM Aix 6.1.6 IBM AIX 6.1.5 IBM AIX 6.1.4 IBM AIX 6.1.3 IBM AIX 6.1.2 IBM AIX 6.1.1 IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3 IBM AIX 5.2 HP HP-UX B.11.31 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 14.0 Avaya CMS Server 13.1 Attachmate Reflection X 14.0.5 Attachmate Reflection X 14.0 Attachmate Reflection X 13.0 Attachmate Reflection for UNIX and OpenVMS 14.0.5 Attachmate Reflection for IBM 14.0.5 Attachmate Reflection for IBM 14 Attachmate Reflection for HP 14.0.5 Attachmate Reflection 13.0.5 Attachmate Reflection 13.0.4 Attachmate Reflection 14.0 SP1 Attachmate Reflection 14.0 Attachmate Reflection 13.0 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.4.11 Apple Mac OS X 10.5.2 Apple Mac OS X 10.4.11 |
| Not Vulnerable: |
X.org xorg-server 1.4.1 Linux Terminal Server Project Linux Terminal Server Project 5.0 Attachmate Reflection X 14.1 Attachmate Reflection 14.1 |
Discussion
X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Server Multiple Local Privilege Escalation and Information Disclosure Vulnerabilities), but has been given its own record to better document the issue.
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Server Multiple Local Privilege Escalation and Information Disclosure Vulnerabilities), but has been given its own record to better document the issue.
Exploit / POC
X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
Solution:
The vendor has released an update and an advisory. Please see the references for more information.
X.org xorg-server 1.4
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
The vendor has released an update and an advisory. Please see the references for more information.
X.org xorg-server 1.4
-
X.org xorg-xserver-1.4-multiple-overflows.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-mu ltiple-overflows.diff
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002PPC.dmg -
Apple SecUpd2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002PPC.dmg -
Apple SecUpdSrvr2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002Univ.dmg
Apple Mac OS X 10.5.2
-
Apple SecUpd2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002.dmg
Apple Mac OS X Server 10.5.2
References
X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
References:
References:
- Multiple Vendor X Server EVI and MIT-SHM Extensions Integer Overflow (iDefense Labs)
- OpenBSD 4.1 Errata Page (OpenBSD)
- OpenBSD 4.2 Errata Page (OpenBSD)
- OpenBSD 4.3 Errata Page (OpenBSD)
- Technical Note 1708 Security Updates and Reflection (Attachmate)
- X.Org Homepage (X.Org)
- iDefense Security Advisory 01.17.08: Multiple Vendor X Server EVI and MIT-SHM (iDefense Labs
) - AIX X server multiple vulnerabilities (IBM)
- ASA-2008-039 Multiple Security Vulnerabilities in the Solaris X Server Extension (Avaya)
- ASA-2008-078 - Multiple Security Vulnerabilities in the Solaris X Server Extensi (Avaya)
- HPSBUX02381 SSRT080083 rev.1 - HP-UX Running Xserver, Remote Execution of Arbitr (HP)
- HPSBUX02381 SSRT080083 rev.2 - HP-UX Running Xserver, Remote Execution of Arbitr (HP)
- RHSA-2008:0029-9 XFree86 security update (Red Hat)
- RHSA-2008:0030-7 xorg-x11 security update (Red Hat)
- RHSA-2008:0031-8 xorg-x11-server security update (Red Hat)
- Solution 200153: Multiple Security Vulnerabilities in the Solaris X Server (Sun Microsystems)
- Sun Alert ID: 103200 Multiple Security Vulnerabilities in the Solaris X Server E (Sun)
- X.Org security advisory, January 17th, 2008 (X.Org)