CVE-2006-6102 — Out-of-bounds Write in X.org
10 documents8 sources
Severity
10.0CRITICALNVD
EPSS
6.4%
top 8.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateMay 1
Description
Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0
Affected Packages2 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-qcrj-j39w-m9qc: Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X↗2022-05-01
CVEList▶
CVE-2006-6102: Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X↗2007-01-09
OSV▶
CVE-2006-6102: Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X↗2006-12-31