X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability
BID:50002
Info
X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability
| Bugtraq ID: | 50002 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-4818 CVE-2010-4819 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 06 2011 12:00AM |
| Updated: | Feb 24 2012 06:00PM |
| Credit: | Vendor |
| Vulnerable: |
X.org X11R7 1.1.1 X.org X11R7 1.0.2 X.org X11R7 1.0.1 X.org X11R7 1.0 X.org X11R7 7.5 X.org X11R7 7.3 X.org X11R7 7.2 X.org X11R7 7.1 X.org X11R7 7.0 X.org X11R6 6.9 X.org X11R6 6.8.2 X.org X11R6 6.8.1 X.org X11R6 6.8 X.org X11R6 6.7 .0 X.org X11R6 5.1 X.org X11R6 4.0 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 5 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Supplementary 6 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 IBM Aix 7.1.1 IBM Aix 7.1 IBM Aix 6.1.7 IBM Aix 6.1.6 IBM AIX 6.1.5 IBM AIX 6.1.4 IBM AIX 6.1.3 IBM AIX 6.1.2 IBM AIX 6.1.1 IBM AIX 7.1 IBM AIX 6.1 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 4.2.2 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 SP2 Avaya Messaging Storage Server 5.1 SP1 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 SP1 Avaya Message Networking 5.2 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 |
| Not Vulnerable: | |
Discussion
X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability
X.Org X11 is prone to multiple local privilege-escalation vulnerabilities and a security vulnerability that may allow attackers to leak arbitrary memory.
An attacker can exploit these issues to execute arbitrary code with elevated privileges, crash the affected computer or gain access to sensitive information. Other attacks are also possible.
X.Org X11 is prone to multiple local privilege-escalation vulnerabilities and a security vulnerability that may allow attackers to leak arbitrary memory.
An attacker can exploit these issues to execute arbitrary code with elevated privileges, crash the affected computer or gain access to sensitive information. Other attacks are also possible.
Exploit / POC
X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability
References:
References:
- (CVE-2010-4819) CVE-2010-4819 X.org: ProcRenderAddGlyphs input sani (Red Hat)
- Memory leak vulnerability in AIX X-server (IBM)
- X.Org Homepage (X.Org)
- (CVE-2010-4818) CVE-2010-4818 X.org: multiple GLX input sanitization flaws (Red Hat)
- ASA-2011-323 xorg-x11 security update (RHSA-2011-1360) (Avaya)
- ASA-2011-325 xorg-x11-server security update (RHSA-2011-1359) (Avaya)