Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 174200
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 174200 depends on: Show dependency tree
Bug 174200 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-04-11 19:58 0000
Seems like it shares some of the same code making it vulnerable to issue on bug
#172575.

Mandriva Linux Security Advisory MDKSA-2007:080-1
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : tightvnc
 Date : April 10, 2007
 Affected: 2007.1
 _______________________________________________________________________

 Problem Description:

 Local exploitation of a memory corruption vulnerability in the X.Org
 and XFree86 X server could allow an attacker to execute arbitrary
 code with privileges of the X server, typically root.

 The vulnerability exists in the ProcXCMiscGetXIDList() function in the
 XC-MISC extension. This request is used to determine what resource IDs
 are available for use. This function contains two vulnerabilities,
 both result in memory corruption of either the stack or heap. The
 ALLOCATE_LOCAL() macro used by this function allocates memory on the
 stack using alloca() on systems where alloca() is present, or using
 the heap otherwise. The handler function takes a user provided value,
 multiplies it, and then passes it to the above macro. This results in
 both an integer overflow vulnerability, and an alloca() stack pointer
 shifting vulnerability. Both can be exploited to execute arbitrary
 code. (CVE-2007-1003)

 iDefense reported two integer overflows in the way X.org handled
 various font files. A malicious local user could exploit these issues
 to potentially execute arbitrary code with the privileges of the
 X.org server. (CVE-2007-1351, CVE-2007-1352)

 TightVNC uses some of the same code base as Xorg, and has the same
 vulnerable code.

 Updated packages are patched to address these issues.

 Update:

 Packages for Mandriva Linux 2007.1 are now available.
 _______________________________________________________________________

 References:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1003
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1351
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1352
 _____________________________________________________

------- Comment #1 From Raúl Porcel 2007-04-11 20:55:18 0000 -------
net-misc/tightvnc-1.2.9-r4 in the tree with those security fixes.

------- Comment #2 From Sune Kloppenborg Jeppesen 2007-04-11 21:00:40 0000 -------
Thx Raul.

Arches please test and mark stable. Target keywords are:

tightvnc-1.2.9-r4.ebuild:KEYWORDS="alpha amd64 ppc sparc x86"

------- Comment #3 From Markus Ullmann 2007-04-11 21:03:33 0000 -------
We're stable on x86 :D

------- Comment #4 From Peter Weller 2007-04-12 06:39:45 0000 -------
amd64 stable

------- Comment #5 From Raúl Porcel 2007-04-12 08:19:45 0000 -------
hppa, you need to stabilize =net-misc/tightvnc-1.3.8-r1

Thanks

------- Comment #6 From Jeroen Roovers 2007-04-12 20:34:58 0000 -------
net-misc/tightvnc-1.3.8-r1 stable for HPPA.

------- Comment #7 From Gustavo Zacarias (RETIRED) 2007-04-13 15:03:08 0000 -------
sparc stable.

------- Comment #8 From Tobias Scherbaum 2007-04-13 15:45:04 0000 -------
ppc stable

------- Comment #9 From Bryan Østergaard (RETIRED) 2007-04-16 23:17:38 0000 -------
Alpha stable.

------- Comment #10 From Raphael Marichez 2007-05-08 20:06:32 0000 -------
GLSA 200705-10 with bug 172575 (libXfont), thanks everybody.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug