X.Org X Server RENDER Extension Integer Overflow Vulnerability
BID:29668
Info
X.Org X Server RENDER Extension Integer Overflow Vulnerability
| Bugtraq ID: | 29668 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2360 CVE-2008-2360 CVE-2008-2360 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 11 2008 12:00AM |
| Updated: | Jun 11 2008 12:00AM |
| Credit: | regenrecht |
| Vulnerable: |
X.org Xserver 1.3 X.org xorg-server 1.4.1 X.org xorg-server 1.4 X.org xorg-server 1.3.99.2 (RC2) X.org xorg-server 1.2 X.org xorg-server 1.02-r5 X.org xorg-server 1.0.2-r6 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_64 Sun OpenSolaris build snv_22 Sun OpenSolaris build snv_19 Sun OpenSolaris build snv_13 Sun OpenSolaris build snv_02 Sun OpenSolaris build snv_01 Sun OpenSolaris 0 Sun Java Desktop System (JDS) 2.0 Slackware Linux 12.1 Slackware Linux -current S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Self-Service - CCSS7 0 NoMachine nx-X11 3.1 -4 NoMachine nx-X11 3.1 -3 NoMachine NX Server 3.1 NoMachine NX Server 2.1 -18 NoMachine NX Server 2.1 -17 NoMachine NX Server 1.4 NoMachine NX Server 1.3.2 NoMachine NX Server 1.3.1 NoMachine NX Server 1.3 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Voice Portal 3.0 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server MM3.0 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Avaya Interactive Response Avaya Integrated Management Avaya CVLAN Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 14.0 Avaya CMS Server 13.1 Attachmate Reflection X 14.0.5 Attachmate Reflection X 14.0 Attachmate Reflection X 13.0 Attachmate Reflection for UNIX and OpenVMS 14.0.5 Attachmate Reflection for IBM 14.0.5 Attachmate Reflection for IBM 14 Attachmate Reflection for HP 14.0.5 Attachmate Reflection 13.0.5 Attachmate Reflection 13.0.4 Attachmate Reflection 14.0 SP1 Attachmate Reflection 14.0 Attachmate Reflection 13.0 |
| Not Vulnerable: |
NoMachine NX Node 3.2 Attachmate Reflection X 14.1 Attachmate Reflection 14.1 |
Discussion
X.Org X Server RENDER Extension Integer Overflow Vulnerability
X Server is prone to an integer-overflow vulnerability because it fails to adequately bounds-check user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary code with superuser privileges. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects all released X Server versions.
X Server is prone to an integer-overflow vulnerability because it fails to adequately bounds-check user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary code with superuser privileges. Failed exploit attempts will likely cause denial-of-service conditions.
This issue affects all released X Server versions.
Exploit / POC
X.Org X Server RENDER Extension Integer Overflow Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
X.Org X Server RENDER Extension Integer Overflow Vulnerability
Solution:
Please see the referenced advisories for more information.
X.org xorg-server 1.02-r5
Sun Solaris 8_sparc
Mandriva Linux Mandrake 2008.0
X.org xorg-server 1.0.2-r6
X.org xorg-server 1.4
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.1
X.org xorg-server 1.4.1
Solution:
Please see the referenced advisories for more information.
X.org xorg-server 1.02-r5
-
X.org xorg-xserver-1.4-cve-2008-2360.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cv e-2008-2360.diff
Sun Solaris 8_sparc
Mandriva Linux Mandrake 2008.0
-
Mandriva libmetisse1-0.4.0-1.rc4.10.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libmetisse1-devel-0.4.0-1.rc4.10.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva metisse-0.4.0-1.rc4.10.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva metisse-fvwm-2.5.20-1.rc4.10.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva x11-server-xmetisse-0.4.0-1.rc4.10.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
X.org xorg-server 1.0.2-r6
-
X.org xorg-xserver-1.4-cve-2008-2360.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cv e-2008-2360.diff
X.org xorg-server 1.4
-
X.org xorg-xserver-1.4-cve-2008-2360.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cv e-2008-2360.diff
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva lib64metisse1-0.4.0-1.rc4.10.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64metisse1-devel-0.4.0-1.rc4.10.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva metisse-0.4.0-1.rc4.10.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva metisse-fvwm-2.5.20-1.rc4.10.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva x11-server-xmetisse-0.4.0-1.rc4.10.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva libmetisse1-0.4.0-1.rc4.10.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libmetisse1-devel-0.4.0-1.rc4.10.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva metisse-0.4.0-1.rc4.10.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva metisse-fvwm-2.5.20-1.rc4.10.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva x11-server-xmetisse-0.4.0-1.rc4.10.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
X.org xorg-server 1.4.1
-
X.org xorg-xserver-1.4-cve-2008-2360.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cv e-2008-2360.diff
References
X.Org X Server RENDER Extension Integer Overflow Vulnerability
References:
References:
- SECURITY - X.org security alert along with the NX Node maintenance release (NoMachine)
- Technical Note 1708 Security Updates and Reflection (Attachmate)
- X.Org Home Page (X.Org)
- iDefense Security Advisory 06.11.08: Multiple Vendor X Server Render Extension (iDefense Labs
) - ASA-2008-249 - Multiple security vulnerabilities in the Solaris X Server Extensi (Avaya)
- ASA-2008-274: xorg-x11 security update (RHSA-2008-0503) (Avaya)
- Multiple Vendor X Server Render Extension AllocateGlyph() Integer Overflow Vulne (iDefense Labs)
- Nortel Response to Sun Alert 238686 - Multiple Security Vulnerabilities in the S (Nortel Networks)
- RHSA-2008:0502-3 XFree86 security update (Red Hat)
- RHSA-2008:0503-2 xorg-x11 security update (Red Hat)
- RHSA-2008:0504-3 xorg-x11-server security update (Red Hat)
- RHSA-2008:0512-3 XFree86 security update (Red Hat)
- Sun Alert 238686 Multiple security vulnerabilities in the Solaris X Server Exten (Sun Microsystems)
- X.Org security advisory june 2008 - Multiple vulnerabilities in X server extensi (X.Org)