CVE-2006-6101
published 2006-12-31CVE-2006-6101: Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to…
PriorityP425medium6.6CVSS 2.0
AVLACMAuSCCICAC
EPSS
0.38%
30.5th percentile
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.1.1-15 (bookworm) | xorg-server 2:1.1.1-15 (bookworm) |
| x.org | x.org | — | — |
| x.org | x.org | — | — |
| x.org | x.org | — | — |
| x.org | x.org | — | — |
| x.org | xorg-server | >= 0 < 2:1.1.1-15 | 2:1.1.1-15 |
| x.org | xorg-server | >= 0 < 2:1.1.1-15 | 2:1.1.1-15 |
| x.org | xorg-server | >= 0 < 2:1.1.1-15 | 2:1.1.1-15 |
| x.org | xorg-server | >= 0 < 2:1.1.1-15 | 2:1.1.1-15 |
CVSS provenance
nvdv2.06.6MEDIUMAV:L/AC:M/Au:S/C:C/I:C/A:C
osv6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vx94-8p32-j95v: Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X
ghsa_unreviewed·2022-05-01
CVE-2006-6101 [MEDIUM] GHSA-vx94-8p32-j95v: Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
OSV
CVE-2006-6101: Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X
osv·2006-12-31·CVSS 6.6
CVE-2006-6101 [MEDIUM] CVE-2006-6101: Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2007-01-09
CVE-2006-6101 X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
The DBE and Render extensions in X.org were vulnerable to integer
overflows, which could lead to memory overwrites. An authenticated user
could make a specially crafted request and execute arbitrary code with
root privileges.
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
security flaw
vendor_redhat·2006-01-09·CVSS 6.6
CVE-2006-6101 [MEDIUM] security flaw
security flaw
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2006-6101: xorg-server - Integer overflow in the ProcRenderAddGlyphs function in the Render extension for...
vendor_debian·2006·CVSS 6.6
CVE-2006-6101 [MEDIUM] CVE-2006-6101: xorg-server - Integer overflow in the ProcRenderAddGlyphs function in the Render extension for...
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
Scope: local
bookworm: resolved (fixed in 2:1.1.1-15)
bullseye: resolved (fixed in 2:1.1.1-15)
forky: resolved (fixed in 2:1.1.1-15)
sid: resolved (fixed in 2:1.1.1-15)
trixie: resolved (fixed in 2:1.1.1-15)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-6101 security flaw
bugzilla·2018-08-16·CVSS 6.6
CVE-2006-6101 [MEDIUM] CVE-2006-6101 security flaw
CVE-2006-6101 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Bugzilla
CVE-2006-6101 Multiple XFree86 integer overflows (CVE-2006-6102, CVE-2006-6103)
bugzilla·2006-12-07·CVSS 6.6
CVE-2006-6101 [MEDIUM] CVE-2006-6101 Multiple XFree86 integer overflows (CVE-2006-6102, CVE-2006-6103)
CVE-2006-6101 Multiple XFree86 integer overflows (CVE-2006-6102, CVE-2006-6103)
iDefense reported several integer overflow flaws in the XFree86 server source.
These flaws may allow a local user to leverage these flaws to become root.
Discussion:
These flaws also affect RHEL2.1
---
Created attachment 143094
Upstream patch
---
Built as XFree86-4.3.0-114.EL for RHEL3.
RHEL 2.1 is waiting for beehive to wake up.
---
XFree86-4.1.0-78.EL for RHEL 2.1
---
correction, -115 for RHEL3.
---
These issues are public:
http://lists.freedesktop.org/archives/xorg-announce/2007-January/000235.html
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution a
Bugzilla
CVE-2006-6101 Multiple xorg-x11 integer overflows (CVE-2006-6102, CVE-2006-6103)
bugzilla·2006-12-07·CVSS 6.6
CVE-2006-6101 [MEDIUM] CVE-2006-6101 Multiple xorg-x11 integer overflows (CVE-2006-6102, CVE-2006-6103)
CVE-2006-6101 Multiple xorg-x11 integer overflows (CVE-2006-6102, CVE-2006-6103)
+++ This bug was initially created as a clone of Bug #218870 +++
iDefense reported several integer overflow flaws in the XFree86 server source.
These flaws may allow a local user to leverage these flaws to become root.
-- Additional comment from [email protected] on 2006-12-07 17:06 EST --
Created an attachment (id=143094)
Upstream patch
Discussion:
Built as xorg-x11-6.8.2-1.EL.13.37.4 for RHEL4.
---
correction, -1.EL.13.37.5 for RHEL5.
---
This issue is public:
http://lists.freedesktop.org/archives/xorg-announce/2007-January/000235.html
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-002.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01075678http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=463http://lists.freedesktop.org/archives/xorg-announce/2007-January/000235.htmlhttp://osvdb.org/32084http://secunia.com/advisories/23633http://secunia.com/advisories/23670http://secunia.com/advisories/23684http://secunia.com/advisories/23689http://secunia.com/advisories/23698http://secunia.com/advisories/23705http://secunia.com/advisories/23758http://secunia.com/advisories/23789http://secunia.com/advisories/23966http://secunia.com/advisories/24168http://secunia.com/advisories/24210http://secunia.com/advisories/24247http://secunia.com/advisories/24401http://secunia.com/advisories/25802http://security.gentoo.org/glsa/glsa-200701-25.xmlhttp://securitytracker.com/id?1017495http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.393555http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1http://support.avaya.com/elmodocs2/security/ASA-2007-066.htmhttp://support.avaya.com/elmodocs2/security/ASA-2007-074.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:005http://www.novell.com/linux/security/advisories/2007_08_x.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0002.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0003.htmlhttp://www.securityfocus.com/bid/21968http://www.ubuntu.com/usn/usn-403-1http://www.vupen.com/english/advisories/2007/0108http://www.vupen.com/english/advisories/2007/0109http://www.vupen.com/english/advisories/2007/0589http://www.vupen.com/english/advisories/2007/0669http://www.vupen.com/english/advisories/2007/2233https://exchange.xforce.ibmcloud.com/vulnerabilities/31337https://issues.rpath.com/browse/RPL-920https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10490https://www.debian.org/security/2007/dsa-1249http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-002.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01075678http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=463http://lists.freedesktop.org/archives/xorg-announce/2007-January/000235.htmlhttp://osvdb.org/32084http://secunia.com/advisories/23633http://secunia.com/advisories/23670http://secunia.com/advisories/23684http://secunia.com/advisories/23689http://secunia.com/advisories/23698http://secunia.com/advisories/23705http://secunia.com/advisories/23758http://secunia.com/advisories/23789http://secunia.com/advisories/23966http://secunia.com/advisories/24168http://secunia.com/advisories/24210http://secunia.com/advisories/24247http://secunia.com/advisories/24401http://secunia.com/advisories/25802http://security.gentoo.org/glsa/glsa-200701-25.xmlhttp://securitytracker.com/id?1017495http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.393555http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1http://support.avaya.com/elmodocs2/security/ASA-2007-066.htmhttp://support.avaya.com/elmodocs2/security/ASA-2007-074.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:005http://www.novell.com/linux/security/advisories/2007_08_x.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0002.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0003.htmlhttp://www.securityfocus.com/bid/21968http://www.ubuntu.com/usn/usn-403-1http://www.vupen.com/english/advisories/2007/0108http://www.vupen.com/english/advisories/2007/0109http://www.vupen.com/english/advisories/2007/0589http://www.vupen.com/english/advisories/2007/0669http://www.vupen.com/english/advisories/2007/2233https://exchange.xforce.ibmcloud.com/vulnerabilities/31337https://issues.rpath.com/browse/RPL-920https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10490https://www.debian.org/security/2007/dsa-1249
2006-12-31
Published