CVE-2007-6429Race Condition in Xserver

Severity
9.3CRITICALNVD
EPSS
2.3%
top 15.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateMay 1

Description

Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDx.org/xserver1.4
Debianx.org/xorg-server< 2:1.4.1~git20080105-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2r2g-x5x8-8vp7: Multiple integer overflows in X2022-05-01
OSV
CVE-2007-6429: Multiple integer overflows in X2008-01-18
CVEList
CVE-2007-6429: Multiple integer overflows in X2008-01-18

📋Vendor Advisories

3
Ubuntu
X.org vulnerabilities2008-01-18
Red Hat
xfree86: integer overflow in EVI extension2008-01-17
Debian
CVE-2007-6429: xorg-server - Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent...2007

💬Community

3
Bugzilla
xorg / XFree86: MIT-SHM part of CVE-2007-6429 fix incomplete2008-02-01
Bugzilla
CVE-2007-6429 xorg / xfree86: integer overflow in MIT-SHM extension2007-12-06
Bugzilla
CVE-2007-6429 xorg / xfree86: integer overflow in EVI extension2007-12-06
CVE-2007-6429 — Race Condition in X.org Xserver | cvebase