CVE-2007-6428Xserver vulnerability

8 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
3.4%
top 12.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateMay 1

Description

The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDx.org/xserver1.4
Debianx.org/xorg-server< 2:1.4.1~git20080105-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x5vw-mf64-c93p: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X2022-05-01
CVEList
CVE-2007-6428: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X2008-01-18
OSV
CVE-2007-6428: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X2008-01-18

📋Vendor Advisories

3
Ubuntu
X.org vulnerabilities2008-01-18
Red Hat
xfree86: information disclosure via TOG-CUP extension2008-01-17
Debian
CVE-2007-6428: xorg-server - The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xs...2007

💬Community

1
Bugzilla
CVE-2007-6428 xorg / xfree86: information disclosure via TOG-CUP extension2007-12-06
CVE-2007-6428 — X.org Xserver vulnerability | cvebase