Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 206633 - x11-base/xorg-server <1.4.1 multiple vulnerabilities (CVE-2007-5760, CVE-2007-5958, CVE-2007-6427, CVE-2007-6428, CVE-2007-6429, CVE-2008-0006)
Summary: x11-base/xorg-server <1.4.1 multiple vulnerabilities (CVE-2007-5760, CVE-2007...
Status: RESOLVED DUPLICATE of bug 204362
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://lists.freedesktop.org/archives...
Whiteboard: A2[ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-01-19 13:13 UTC by Lars Hartmann
Modified: 2008-01-19 14:17 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2008-01-19 13:13:37 UTC
Overview

Several vulnerabilities have been identified in server code of the X
window system caused by lack of proper input validation on user
controlled data in various parts of the software, causing various
kinds of overflows.


Impact

Exploiting these overflows will crash the X server or,
under certain circumstances allow the execution of arbitray machine code.

When the X server is running with root privileges (which is the case
for the Xorg server and for most kdrive based servers), these
vulnerabilities can thus also be used to raise privileges.

All these vulnerabilities, to be exploited succesfully, require either
an already established connection to a running X server (and normally
running X servers are only accepting authenticated connections), or a
shell access with a valid user on the machine where the vulnerable
server is installed.

Solution: update to 1.4.1
Comment 1 Lars Hartmann 2008-01-19 13:18:22 UTC
maintainers - please provide an updated ebuild
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2008-01-19 14:17:00 UTC
Well hum, it's already fixed in the tree.

*** This bug has been marked as a duplicate of bug 204362 ***