CVE-2007-5760Xserver vulnerability

8 documents8 sources
Severity
9.3CRITICALNVD
EPSS
4.4%
top 10.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateMay 1

Description

Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDx.org/xserver1.4
Debianx.org/xorg-server< 2:1.4.1~git20080105-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6grr-7qqf-x376: Array index error in the XFree86-Misc extension in X2022-05-01
CVEList
CVE-2007-5760: Array index error in the XFree86-Misc extension in X2008-01-18
OSV
CVE-2007-5760: Array index error in the XFree86-Misc extension in X2008-01-18

📋Vendor Advisories

3
Ubuntu
X.org vulnerabilities2008-01-18
Red Hat
xorg: invalid array indexing in XFree86-Misc extension2008-01-17
Debian
CVE-2007-5760: xorg-server - Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 al...2007

💬Community

1
Bugzilla
CVE-2007-5760 xorg: invalid array indexing in XFree86-Misc extension2007-12-06
CVE-2007-5760 — X.org Xserver vulnerability | cvebase