CVE-2007-6429
published 2008-01-18CVE-2007-6429: Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.50%
83.0th percentile
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.4.1~git20080105-2 (bookworm) | xorg-server 2:1.4.1~git20080105-2 (bookworm) |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xserver | <= 1.4 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.org regression
vendor_ubuntu·2008-01-19·CVSS 9.3
[CRITICAL] X.org regression
Title: X.org regression
Summary: X.org regression
USN-571-1 fixed vulnerabilities in X.org. The upstream fixes were
incomplete, and under certain situations, applications using the MIT-SHM
extension (e.g. Java, wxWidgets) would crash with BadAlloc X errors.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
function arguments. An authenticated attacker could send specially
crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
CVE-2007-6428, CVE-2007-6429)
It was discovered that the X.org server did not use user privileges when
attempting to open security policy files. Local attackers c
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2008-01-18·CVSS 9.3
CVE-2008-0006 [CRITICAL] X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
function arguments. An authenticated attacker could send specially
crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
CVE-2007-6428, CVE-2007-6429)
It was discovered that the X.org server did not use user privileges when
attempting to open security policy files. Local attackers could exploit
this to probe for files in directories they would not normally be able
to access. (CVE-2007-5958)
It was discovered that the PCF font handling code did not correctly
validate the size of fonts. An authenticated attacker could load a
specially crafted font and gain additional privi
Red Hat
xfree86: integer overflow in EVI extension
vendor_redhat·2008-01-17·CVSS 9.3
CVE-2007-6429 [CRITICAL] CWE-190 xfree86: integer overflow in EVI extension
xfree86: integer overflow in EVI extension
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.
Debian
CVE-2007-6429: xorg-server - Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent...
vendor_debian·2007·CVSS 9.3
CVE-2007-6429 [CRITICAL] CVE-2007-6429: xorg-server - Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent...
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.
Scope: local
bookworm: resolved (fixed in 2:1.4.1~git20080105-2)
bullseye: resolved (fixed in 2:1.4.1~git20080105-2)
forky: resolved (fixed in 2:1.4.1~git20080105-2)
sid: resolved (fixed in 2:1.4.1~git20080105-2)
trixie: resolved (fixed in 2:1.4.1~git20080105-2)
GHSA
GHSA-2r2g-x5x8-8vp7: Multiple integer overflows in X
ghsa_unreviewed·2022-05-01
CVE-2007-6429 [HIGH] GHSA-2r2g-x5x8-8vp7: Multiple integer overflows in X
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.
OSV
CVE-2007-6429: Multiple integer overflows in X
osv·2008-01-18·CVSS 9.3
CVE-2007-6429 [CRITICAL] CVE-2007-6429: Multiple integer overflows in X
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.
No detection rules found.
No public exploits indexed.
Bugzilla
xorg / XFree86: MIT-SHM part of CVE-2007-6429 fix incomplete
bugzilla·2008-02-01·CVSS 9.3
CVE-2007-6429 [CRITICAL] xorg / XFree86: MIT-SHM part of CVE-2007-6429 fix incomplete
xorg / XFree86: MIT-SHM part of CVE-2007-6429 fix incomplete
Following Gentoo bug report points out that fix addressing integer overflow in
MIT-SHM extension (part of CVE-2007-6429, originally tracked via bug #413741) is
incomplete and may not properly protect against overflow for certain bit depths:
http://bugs.gentoo.org/show_bug.cgi?id=208343
Upstream git commit that should address this problem:
http://gitweb.freedesktop.org/?p=xorg/xserver.git;a=commit;h=be6c17fcf9efebc0bbcc3d9a25f8c5a2450c2161
Discussion:
Related discussion in the original upstream bug report for MIT-SHM overflow:
https://bugs.freedesktop.org/show_bug.cgi?id=13520#c9
---
Yeah, should pull this in.
---
On reflection, this subsequent change is unnecessary.
One bit of seemingly irrelevant trivia before we get
Bugzilla
CVE-2007-6429 xorg / xfree86: integer overflow in MIT-SHM extension
bugzilla·2007-12-06·CVSS 9.3
CVE-2007-6429 [CRITICAL] CVE-2007-6429 xorg / xfree86: integer overflow in MIT-SHM extension
CVE-2007-6429 xorg / xfree86: integer overflow in MIT-SHM extension
iDefense reported a vulnerability discovered by regenrecht affecting Xorg X server:
DESCRIPTION
Local exploitation of an integer overflow vulnerability in the X.Org X
server, as included in various vendors' operating system distributions,
could allow an attacker to execute arbitrary code with the privileges of
the X server, typically root.
The vulnerability exists within the code responsible for creating a
pixmap in shared memory. When allocating the pixmap, the server uses
values from the request to verify that the requested size is not
greater than the allocated shared memory. The calculation can overflow,
which leads to the overwriting of arbitrary addresses in memory that
aren't part of the shared memory segment.
Bugzilla
CVE-2007-6429 xorg / xfree86: integer overflow in EVI extension
bugzilla·2007-12-06·CVSS 9.3
CVE-2007-6429 [CRITICAL] CVE-2007-6429 xorg / xfree86: integer overflow in EVI extension
CVE-2007-6429 xorg / xfree86: integer overflow in EVI extension
iDefense reported a vulnerability discovered by regenrecht affecting Xorg X server:
DESCRIPTION
Local exploitation of an integer overflow vulnerability in the X.Org X
server, as included in various vendors' operating system distributions,
could allow an attacker to execute arbitrary code with the privileges of
the X server, typically root.
The vulnerability exists within the code responsible for processing the
GetVisualInfo request. When processing this request, the server uses a
32-bit value provided by the client in an arithmetic operation that
calculates the number of bytes to allocate for a dynamic buffer. This
operation can overflow, which later leads to the buffer being
overflowed.
The vulnerable code is shown below
http://bugs.gentoo.org/show_bug.cgi?id=204362http://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=645http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/28273http://secunia.com/advisories/28532http://secunia.com/advisories/28535http://secunia.com/advisories/28536http://secunia.com/advisories/28539http://secunia.com/advisories/28540http://secunia.com/advisories/28542http://secunia.com/advisories/28543http://secunia.com/advisories/28550http://secunia.com/advisories/28584http://secunia.com/advisories/28592http://secunia.com/advisories/28616http://secunia.com/advisories/28693http://secunia.com/advisories/28718http://secunia.com/advisories/28838http://secunia.com/advisories/28843http://secunia.com/advisories/28885http://secunia.com/advisories/28941http://secunia.com/advisories/29139http://secunia.com/advisories/29420http://secunia.com/advisories/29622http://secunia.com/advisories/29707http://secunia.com/advisories/30161http://secunia.com/advisories/32545http://security.gentoo.org/glsa/glsa-200801-09.xmlhttp://security.gentoo.org/glsa/glsa-200804-05.xmlhttp://securitytracker.com/id?1019232http://sunsolve.sun.com/search/document.do?assetkey=1-26-103200-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-200153-1http://support.avaya.com/elmodocs2/security/ASA-2008-039.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-078.htmhttp://www.debian.org/security/2008/dsa-1466http://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:021http://www.mandriva.com/security/advisories?name=MDVSA-2008:022http://www.mandriva.com/security/advisories?name=MDVSA-2008:023http://www.mandriva.com/security/advisories?name=MDVSA-2008:025http://www.openbsd.org/errata41.html#012_xorghttp://www.openbsd.org/errata42.html#006_xorghttp://www.redhat.com/support/errata/RHSA-2008-0029.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0030.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0031.htmlhttp://www.securityfocus.com/archive/1/487335/100/0/threadedhttp://www.securityfocus.com/bid/27336http://www.securityfocus.com/bid/27350http://www.securityfocus.com/bid/27353http://www.vupen.com/english/advisories/2008/0179http://www.vupen.com/english/advisories/2008/0184http://www.vupen.com/english/advisories/2008/0497/referenceshttp://www.vupen.com/english/advisories/2008/0703http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/3000http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile112539&label=AIX%20X%20server%20multiple%20vulnerabilitieshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39763https://exchange.xforce.ibmcloud.com/vulnerabilities/39764https://issues.rpath.com/browse/RPL-2010https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11045https://usn.ubuntu.com/571-1/https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=204362http://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=645http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/28273http://secunia.com/advisories/28532http://secunia.com/advisories/28535http://secunia.com/advisories/28536http://secunia.com/advisories/28539http://secunia.com/advisories/28540http://secunia.com/advisories/28542http://secunia.com/advisories/28543http://secunia.com/advisories/28550http://secunia.com/advisories/28584http://secunia.com/advisories/28592http://secunia.com/advisories/28616http://secunia.com/advisories/28693http://secunia.com/advisories/28718http://secunia.com/advisories/28838http://secunia.com/advisories/28843http://secunia.com/advisories/28885http://secunia.com/advisories/28941http://secunia.com/advisories/29139http://secunia.com/advisories/29420http://secunia.com/advisories/29622http://secunia.com/advisories/29707
+ 38 more references
2008-01-18
Published