CVE-2007-6428
published 2008-01-18CVE-2007-6428: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.74%
75.3th percentile
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.4.1~git20080105-2 (bookworm) | xorg-server 2:1.4.1~git20080105-2 (bookworm) |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xserver | <= 1.4 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_ubuntu9.3CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.org regression
vendor_ubuntu·2008-01-19·CVSS 9.3
[CRITICAL] X.org regression
Title: X.org regression
Summary: X.org regression
USN-571-1 fixed vulnerabilities in X.org. The upstream fixes were
incomplete, and under certain situations, applications using the MIT-SHM
extension (e.g. Java, wxWidgets) would crash with BadAlloc X errors.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
function arguments. An authenticated attacker could send specially
crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
CVE-2007-6428, CVE-2007-6429)
It was discovered that the X.org server did not use user privileges when
attempting to open security policy files. Local attackers c
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2008-01-18·CVSS 9.3
CVE-2008-0006 [CRITICAL] X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
function arguments. An authenticated attacker could send specially
crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
CVE-2007-6428, CVE-2007-6429)
It was discovered that the X.org server did not use user privileges when
attempting to open security policy files. Local attackers could exploit
this to probe for files in directories they would not normally be able
to access. (CVE-2007-5958)
It was discovered that the PCF font handling code did not correctly
validate the size of fonts. An authenticated attacker could load a
specially crafted font and gain additional privi
Red Hat
xfree86: information disclosure via TOG-CUP extension
vendor_redhat·2008-01-17·CVSS 5.0
CVE-2007-6428 [MEDIUM] xfree86: information disclosure via TOG-CUP extension
xfree86: information disclosure via TOG-CUP extension
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.
Debian
CVE-2007-6428: xorg-server - The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xs...
vendor_debian·2007·CVSS 5.0
CVE-2007-6428 [MEDIUM] CVE-2007-6428: xorg-server - The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xs...
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.
Scope: local
bookworm: resolved (fixed in 2:1.4.1~git20080105-2)
bullseye: resolved (fixed in 2:1.4.1~git20080105-2)
forky: resolved (fixed in 2:1.4.1~git20080105-2)
sid: resolved (fixed in 2:1.4.1~git20080105-2)
trixie: resolved (fixed in 2:1.4.1~git20080105-2)
GHSA
GHSA-x5vw-mf64-c93p: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X
ghsa_unreviewed·2022-05-01
CVE-2007-6428 [MEDIUM] GHSA-x5vw-mf64-c93p: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.
OSV
CVE-2007-6428: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X
osv·2008-01-18·CVSS 5.0
CVE-2007-6428 [MEDIUM] CVE-2007-6428: The ProcGetReservedColormapEntries function in the TOG-CUP extension in X
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=204362http://docs.info.apple.com/article.html?artnum=307562http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=644http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/28273http://secunia.com/advisories/28532http://secunia.com/advisories/28535http://secunia.com/advisories/28536http://secunia.com/advisories/28539http://secunia.com/advisories/28540http://secunia.com/advisories/28542http://secunia.com/advisories/28543http://secunia.com/advisories/28550http://secunia.com/advisories/28584http://secunia.com/advisories/28592http://secunia.com/advisories/28616http://secunia.com/advisories/28693http://secunia.com/advisories/28718http://secunia.com/advisories/28838http://secunia.com/advisories/28843http://secunia.com/advisories/28885http://secunia.com/advisories/28941http://secunia.com/advisories/29139http://secunia.com/advisories/29420http://secunia.com/advisories/29622http://secunia.com/advisories/29707http://secunia.com/advisories/30161http://security.gentoo.org/glsa/glsa-200801-09.xmlhttp://security.gentoo.org/glsa/glsa-200804-05.xmlhttp://securitytracker.com/id?1019232http://sunsolve.sun.com/search/document.do?assetkey=1-26-103200-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-200153-1http://support.avaya.com/elmodocs2/security/ASA-2008-039.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-078.htmhttp://www.debian.org/security/2008/dsa-1466http://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:021http://www.mandriva.com/security/advisories?name=MDVSA-2008:022http://www.mandriva.com/security/advisories?name=MDVSA-2008:023http://www.mandriva.com/security/advisories?name=MDVSA-2008:025http://www.openbsd.org/errata41.html#012_xorghttp://www.openbsd.org/errata42.html#006_xorghttp://www.redhat.com/support/errata/RHSA-2008-0029.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0030.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0031.htmlhttp://www.securityfocus.com/archive/1/487335/100/0/threadedhttp://www.securityfocus.com/bid/27336http://www.securityfocus.com/bid/27355http://www.vupen.com/english/advisories/2008/0179http://www.vupen.com/english/advisories/2008/0184http://www.vupen.com/english/advisories/2008/0497/referenceshttp://www.vupen.com/english/advisories/2008/0703http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile112539&label=AIX%20X%20server%20multiple%20vulnerabilitieshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39761https://issues.rpath.com/browse/RPL-2010https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11754https://usn.ubuntu.com/571-1/https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=204362http://docs.info.apple.com/article.html?artnum=307562http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=644http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/28273http://secunia.com/advisories/28532http://secunia.com/advisories/28535http://secunia.com/advisories/28536http://secunia.com/advisories/28539http://secunia.com/advisories/28540http://secunia.com/advisories/28542http://secunia.com/advisories/28543http://secunia.com/advisories/28550http://secunia.com/advisories/28584http://secunia.com/advisories/28592http://secunia.com/advisories/28616http://secunia.com/advisories/28693http://secunia.com/advisories/28718http://secunia.com/advisories/28838http://secunia.com/advisories/28843http://secunia.com/advisories/28885http://secunia.com/advisories/28941http://secunia.com/advisories/29139http://secunia.com/advisories/29420http://secunia.com/advisories/29622http://secunia.com/advisories/29707http://secunia.com/advisories/30161http://security.gentoo.org/glsa/glsa-200801-09.xmlhttp://security.gentoo.org/glsa/glsa-200804-05.xmlhttp://securitytracker.com/id?1019232http://sunsolve.sun.com/search/document.do?assetkey=1-26-103200-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-200153-1
+ 28 more references
2008-01-18
Published