CVE-2007-4730
published 2007-09-11CVE-2007-4730: Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute…
PriorityP419medium4.3CVSS 2.0
AVLACLAuSCPIPAP
EPSS
0.51%
40.6th percentile
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.4-1 (bookworm) | xorg-server 2:1.4-1 (bookworm) |
| x.org | xorg-server | — | — |
| x.org | xorg-server | — | — |
| x.org | xorg-server | — | — |
| x.org | xorg-server | — | — |
| x.org | xorg-server | — | — |
| x.org | xorg-server | >= 0 < 2:1.4-1 | 2:1.4-1 |
| x.org | xorg-server | >= 0 < 2:1.4-1 | 2:1.4-1 |
| x.org | xorg-server | >= 0 < 2:1.4-1 | 2:1.4-1 |
| x.org | xorg-server | >= 0 < 2:1.4-1 | 2:1.4-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.org vulnerability
vendor_ubuntu·2007-09-18
CVE-2007-4730 X.org vulnerability
Title: X.org vulnerability
Summary: X.org vulnerability
Aaron Plattner discovered that the Composite extension did not correctly
calculate the size of buffers when copying between different bit depths.
An authenticated user could exploit this to execute arbitrary code with
root privileges.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
X.org composite extension buffer overflow
vendor_redhat·2007-09-09·CVSS 4.3
CVE-2007-4730 [MEDIUM] X.org composite extension buffer overflow
X.org composite extension buffer overflow
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.
Statement: Red Hat Enterprise Linux 5 is not affected by this flaw. More information can be found here:
https://bugzilla.redhat.com/show_bug.cgi?id=285991
Red Hat Enterprise Linux 2.1 and 3 do not support the composite extension and are not vulnerable to this flaw.
Debian
CVE-2007-4730: xorg-server - Buffer overflow in the compNewPixmap function in compalloc.c in the Composite ex...
vendor_debian·2007·CVSS 4.3
CVE-2007-4730 [MEDIUM] CVE-2007-4730: xorg-server - Buffer overflow in the compNewPixmap function in compalloc.c in the Composite ex...
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.
Scope: local
bookworm: resolved (fixed in 2:1.4-1)
bullseye: resolved (fixed in 2:1.4-1)
forky: resolved (fixed in 2:1.4-1)
sid: resolved (fixed in 2:1.4-1)
trixie: resolved (fixed in 2:1.4-1)
GHSA
GHSA-737c-wj7m-pqqr: Buffer overflow in the compNewPixmap function in compalloc
ghsa_unreviewed·2022-05-01
CVE-2007-4730 [MEDIUM] CWE-119 GHSA-737c-wj7m-pqqr: Buffer overflow in the compNewPixmap function in compalloc
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.
OSV
CVE-2007-4730: Buffer overflow in the compNewPixmap function in compalloc
osv·2007-09-11·CVSS 4.3
CVE-2007-4730 [MEDIUM] CVE-2007-4730: Buffer overflow in the compNewPixmap function in compalloc
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-4730 X.org composite extension buffer overflow
bugzilla·2007-09-11·CVSS 4.3
CVE-2007-4730 [MEDIUM] CVE-2007-4730 X.org composite extension buffer overflow
CVE-2007-4730 X.org composite extension buffer overflow
A buffer overflow flaw has been found in the X.org composite extension. The
upstream bug has more details:
http://bugs.freedesktop.org/show_bug.cgi?id=7447
By running a server at depth 16, it becomes possible for a local user to
overflow a buffer by creating a window with depth 32, then resizing it.
Discussion:
FC6, F7, Fdevel, and rhels 5.0.z, 5.1 are not vulnerable because of this patch:
localhost:~/vertigo/rpms/xorg-x11-server/RHEL-5% cat
xorg-x11-server-1.1.0-dont-backfill-bg-none.patch
Disable backfilling of windows created with bg=none, which otherwise
would force a framebuffer readback.
--- ./composite/compalloc.c.spiffiffity 2006-03-13 16:59:55.000000000 -0500
+++ ./composite/compalloc.c 2006-04-12 16:37:50.000000000 -0
Bugzilla
CVE-2007-4730 X.org composite extension buffer overflow [F7]
bugzilla·2007-09-11·CVSS 4.3
CVE-2007-4730 [MEDIUM] CVE-2007-4730 X.org composite extension buffer overflow [F7]
CVE-2007-4730 X.org composite extension buffer overflow [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
WONTFIXing, F7 is not vulnerable to this.
Bugzilla
CVE-2007-4730 X.org composite extension buffer overflow [Fdevel]
bugzilla·2007-09-11·CVSS 4.3
CVE-2007-4730 [MEDIUM] CVE-2007-4730 X.org composite extension buffer overflow [Fdevel]
CVE-2007-4730 X.org composite extension buffer overflow [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2007-4730 X.org composite extension buffer overflow [FC6]
bugzilla·2007-09-11·CVSS 4.3
CVE-2007-4730 [MEDIUM] CVE-2007-4730 X.org composite extension buffer overflow [FC6]
CVE-2007-4730 X.org composite extension buffer overflow [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
WONTFIXing, Fedora Core 6 is not vulnerable to this.
http://bugs.freedesktop.org/show_bug.cgi?id=7447http://bugs.gentoo.org/show_bug.cgi?id=191964http://lists.freedesktop.org/archives/xorg-announce/2007-September/000378.htmlhttp://osvdb.org/37726http://secunia.com/advisories/26743http://secunia.com/advisories/26755http://secunia.com/advisories/26763http://secunia.com/advisories/26823http://secunia.com/advisories/26859http://secunia.com/advisories/26897http://secunia.com/advisories/27147http://secunia.com/advisories/27179http://secunia.com/advisories/27228http://secunia.com/advisories/30161http://security.gentoo.org/glsa/glsa-200710-16.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-394.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2007-0187http://www.debian.org/security/2007/dsa-1372http://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:178http://www.mandriva.com/security/advisories?name=MDVSA-2008:022http://www.novell.com/linux/security/advisories/2007_54_xorg.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0898.htmlhttp://www.securityfocus.com/bid/25606http://www.securitytracker.com/id?1018665http://www.ubuntu.com/usn/usn-514-1http://www.vupen.com/english/advisories/2007/3098https://exchange.xforce.ibmcloud.com/vulnerabilities/36535https://issues.rpath.com/browse/RPL-1728https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10430http://bugs.freedesktop.org/show_bug.cgi?id=7447http://bugs.gentoo.org/show_bug.cgi?id=191964http://lists.freedesktop.org/archives/xorg-announce/2007-September/000378.htmlhttp://osvdb.org/37726http://secunia.com/advisories/26743http://secunia.com/advisories/26755http://secunia.com/advisories/26763http://secunia.com/advisories/26823http://secunia.com/advisories/26859http://secunia.com/advisories/26897http://secunia.com/advisories/27147http://secunia.com/advisories/27179http://secunia.com/advisories/27228http://secunia.com/advisories/30161http://security.gentoo.org/glsa/glsa-200710-16.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-394.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2007-0187http://www.debian.org/security/2007/dsa-1372http://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:178http://www.mandriva.com/security/advisories?name=MDVSA-2008:022http://www.novell.com/linux/security/advisories/2007_54_xorg.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0898.htmlhttp://www.securityfocus.com/bid/25606http://www.securitytracker.com/id?1018665http://www.ubuntu.com/usn/usn-514-1http://www.vupen.com/english/advisories/2007/3098https://exchange.xforce.ibmcloud.com/vulnerabilities/36535https://issues.rpath.com/browse/RPL-1728https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10430
2007-09-11
Published