CVE-2007-1003
published 2007-04-06CVE-2007-1003: Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other…
PriorityP340critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
5.25%
91.7th percentile
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.1.1-21 (bookworm) | xorg-server 2:1.1.1-21 (bookworm) |
| x.org | x11 | — | — |
| x.org | xorg-server | >= 0 < 2:1.1.1-21 | 2:1.1.1-21 |
| x.org | xorg-server | >= 0 < 2:1.1.1-21 | 2:1.1.1-21 |
| x.org | xorg-server | >= 0 < 2:1.1.1-21 | 2:1.1.1-21 |
| x.org | xorg-server | >= 0 < 2:1.1.1-21 | 2:1.1.1-21 |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.0CRITICAL
vendor_debian9.0MEDIUM
vendor_redhat9.0CRITICAL
vendor_ubuntu9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qh64-49gx-35pg: Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X
ghsa_unreviewed·2022-05-01
CVE-2007-1003 [HIGH] GHSA-qh64-49gx-35pg: Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.
OSV
CVE-2007-1003: Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X
osv·2007-04-06·CVSS 9.0
CVE-2007-1003 [CRITICAL] CVE-2007-1003: Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2007-04-03·CVSS 9.0
CVE-2007-1351 [CRITICAL] X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
Sean Larsson of iDefense Labs discovered that the MISC-XC extension of
Xorg did not correctly verify the size of allocated memory. An
authenticated user could send a specially crafted X11 request and
execute arbitrary code with root privileges. (CVE-2007-1003)
Greg MacManus of iDefense Labs discovered that the BDF font handling
code in Xorg and FreeType did not correctly verify the size of allocated
memory. If a user were tricked into using a specially crafted font, a
remote attacker could execute arbitrary code with root privileges.
(CVE-2007-1351, CVE-2007-1352)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
xserver XC-MISC integer overflow
vendor_redhat·2007-04-03·CVSS 9.0
CVE-2007-1003 [CRITICAL] xserver XC-MISC integer overflow
xserver XC-MISC integer overflow
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.
Debian
CVE-2007-1003: xorg-server - Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the X...
vendor_debian·2007·CVSS 9.0
CVE-2007-1003 [CRITICAL] CVE-2007-1003: xorg-server - Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the X...
Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.
Scope: local
bookworm: resolved (fixed in 2:1.1.1-21)
bullseye: resolved (fixed in 2:1.1.1-21)
forky: resolved (fixed in 2:1.1.1-21)
sid: resolved (fixed in 2:1.1.1-21)
trixie: resolved (fixed in 2:1.1.1-21)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-1003 xserver XC-MISC integer overflow
bugzilla·2007-04-04·CVSS 9.0
CVE-2007-1003 [CRITICAL] CVE-2007-1003 xserver XC-MISC integer overflow
CVE-2007-1003 xserver XC-MISC integer overflow
+++ This bug was initially created as a clone of Bug #233001 +++
+++ This bug was initially created as a clone of Bug #233000 +++
Sean Larsson, iDefense Labs, discovered an integer overflow flaw in the XC-MISC
extension. This overflow could allow a local user to gain root privileges.
-- Additional comment from [email protected] on 2007-03-19 16:10 EST --
Created an attachment (id=150431)
Poposed upstream patch
This flaw also affects FC5
Discussion:
These have been pushed.
Bugzilla
CVE-2007-1003 xserver XC-MISC integer overflow
bugzilla·2007-03-19·CVSS 9.0
CVE-2007-1003 [CRITICAL] CVE-2007-1003 xserver XC-MISC integer overflow
CVE-2007-1003 xserver XC-MISC integer overflow
+++ This bug was initially created as a clone of Bug #233000 +++
Sean Larsson, iDefense Labs, discovered an integer overflow flaw in the XC-MISC
extension. This overflow could allow a local user to gain root privileges.
-- Additional comment from [email protected] on 2007-03-19 16:10 EST --
Created an attachment (id=150431)
Poposed upstream patch
Discussion:
Lifting embargo
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/R
Bugzilla
CVE-2007-1003 xserver XC-MISC integer overflow
bugzilla·2007-03-19·CVSS 9.0
CVE-2007-1003 [CRITICAL] CVE-2007-1003 xserver XC-MISC integer overflow
CVE-2007-1003 xserver XC-MISC integer overflow
Sean Larsson, iDefense Labs, discovered an integer overflow flaw in the XC-MISC
extension. This overflow could allow a local user to gain root privileges.
Discussion:
This flaw also affects RHEL2.1
---
Created attachment 150431
Poposed upstream patch
---
2.1 is building. NVR: XFree86-4.1.0-80EL
---
3 is building. NVR: XFree86-4.3.0-118_EL
http://brewweb.devel.redhat.com/brew/taskinfo?taskID=681192
---
Lifting embargo.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does
Bugzilla
CVE-2007-1003 xserver XC-MISC integer overflow
bugzilla·2007-03-19·CVSS 9.0
CVE-2007-1003 [CRITICAL] CVE-2007-1003 xserver XC-MISC integer overflow
CVE-2007-1003 xserver XC-MISC integer overflow
+++ This bug was initially created as a clone of Bug #232996 +++
Sean Larsson, iDefense Labs, discovered an integer overflow flaw in the XC-MISC
extension. This overflow could allow a local user to gain root privileges.
-- Additional comment from [email protected] on 2007-03-19 16:10 EST --
Created an attachment (id=150431)
Poposed upstream patch
Discussion:
Lifting embargo
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/R
http://issues.foresightlinux.org/browse/FL-223http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=503http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2007-0125.htmlhttp://secunia.com/advisories/24741http://secunia.com/advisories/24745http://secunia.com/advisories/24756http://secunia.com/advisories/24758http://secunia.com/advisories/24765http://secunia.com/advisories/24770http://secunia.com/advisories/24771http://secunia.com/advisories/24772http://secunia.com/advisories/24791http://secunia.com/advisories/25004http://secunia.com/advisories/25006http://secunia.com/advisories/25195http://secunia.com/advisories/25216http://secunia.com/advisories/25305http://secunia.com/advisories/29622http://security.gentoo.org/glsa/glsa-200705-10.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1http://support.avaya.com/elmodocs2/security/ASA-2007-178.htmhttp://www.debian.org/security/2007/dsa-1294http://www.mandriva.com/security/advisories?name=MDKSA-2007:079http://www.mandriva.com/security/advisories?name=MDKSA-2007:080http://www.novell.com/linux/security/advisories/2007_27_x.htmlhttp://www.openbsd.org/errata39.html#021_xorghttp://www.openbsd.org/errata40.html#011_xorghttp://www.redhat.com/support/errata/RHSA-2007-0126.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0127.htmlhttp://www.securityfocus.com/archive/1/464686/100/0/threadedhttp://www.securityfocus.com/archive/1/464816/100/0/threadedhttp://www.securityfocus.com/bid/23284http://www.securityfocus.com/bid/23300http://www.securitytracker.com/id?1017857http://www.ubuntu.com/usn/usn-448-1http://www.vupen.com/english/advisories/2007/1217http://www.vupen.com/english/advisories/2007/1548https://exchange.xforce.ibmcloud.com/vulnerabilities/33424https://issues.rpath.com/browse/RPL-1213https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1980https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9798http://issues.foresightlinux.org/browse/FL-223http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=503http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2007-0125.htmlhttp://secunia.com/advisories/24741http://secunia.com/advisories/24745http://secunia.com/advisories/24756http://secunia.com/advisories/24758http://secunia.com/advisories/24765http://secunia.com/advisories/24770http://secunia.com/advisories/24771http://secunia.com/advisories/24772http://secunia.com/advisories/24791http://secunia.com/advisories/25004http://secunia.com/advisories/25006http://secunia.com/advisories/25195http://secunia.com/advisories/25216http://secunia.com/advisories/25305http://secunia.com/advisories/29622http://security.gentoo.org/glsa/glsa-200705-10.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1http://support.avaya.com/elmodocs2/security/ASA-2007-178.htmhttp://www.debian.org/security/2007/dsa-1294http://www.mandriva.com/security/advisories?name=MDKSA-2007:079http://www.mandriva.com/security/advisories?name=MDKSA-2007:080http://www.novell.com/linux/security/advisories/2007_27_x.htmlhttp://www.openbsd.org/errata39.html#021_xorghttp://www.openbsd.org/errata40.html#011_xorghttp://www.redhat.com/support/errata/RHSA-2007-0126.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0127.htmlhttp://www.securityfocus.com/archive/1/464686/100/0/threadedhttp://www.securityfocus.com/archive/1/464816/100/0/threadedhttp://www.securityfocus.com/bid/23284http://www.securityfocus.com/bid/23300http://www.securitytracker.com/id?1017857http://www.ubuntu.com/usn/usn-448-1http://www.vupen.com/english/advisories/2007/1217http://www.vupen.com/english/advisories/2007/1548https://exchange.xforce.ibmcloud.com/vulnerabilities/33424https://issues.rpath.com/browse/RPL-1213https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1980https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9798
2007-04-06
Published