CVE-2008-1379
published 2008-06-16CVE-2008-1379: Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read…
PriorityP428medium6.8CVSS 2.0
AVNACLAuSCCINAN
EPSS
1.39%
69.4th percentile
Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.4.1~git20080517-2 (bookworm) | xorg-server 2:1.4.1~git20080517-2 (bookworm) |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x | x11 | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
osv6.8MEDIUM
vendor_ubuntu9.0CRITICAL
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2008-06-13·CVSS 9.0
CVE-2008-2362 [CRITICAL] X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
Multiple flaws were found in the RENDER, RECORD, and Security
extensions of X.org which did not correctly validate function arguments.
An authenticated attacker could send specially crafted requests and gain
root privileges or crash X. (CVE-2008-1377, CVE-2008-2360, CVE-2008-2361,
CVE-2008-2362)
It was discovered that the MIT-SHM extension of X.org did not correctly
validate the location of memory during an image copy. An authenticated
attacker could exploit this to read arbitrary memory locations within X,
exposing sensitive information. (CVE-2008-1379)
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
X.org MIT-SHM extension arbitrary memory read
vendor_redhat·2008-06-11·CVSS 6.8
CVE-2008-1379 [MEDIUM] X.org MIT-SHM extension arbitrary memory read
X.org MIT-SHM extension arbitrary memory read
Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.
Debian
CVE-2008-1379: xorg-server - Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X...
vendor_debian·2008·CVSS 6.8
CVE-2008-1379 [MEDIUM] CVE-2008-1379: xorg-server - Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X...
Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.
Scope: local
bookworm: resolved (fixed in 2:1.4.1~git20080517-2)
bullseye: resolved (fixed in 2:1.4.1~git20080517-2)
forky: resolved (fixed in 2:1.4.1~git20080517-2)
sid: resolved (fixed in 2:1.4.1~git20080517-2)
trixie: resolved (fixed in 2:1.4.1~git20080517-2)
GHSA
GHSA-6524-8pr6-358q: Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1
ghsa_unreviewed·2022-05-03
CVE-2008-1379 [MEDIUM] GHSA-6524-8pr6-358q: Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1
Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.
OSV
CVE-2008-1379: Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1
osv·2008-06-16·CVSS 6.8
CVE-2008-1379 [MEDIUM] CVE-2008-1379: Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1
Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.
No detection rules found.
No public exploits indexed.
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-1379.diffhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=722http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.freedesktop.org/archives/xorg/2008-June/036026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0502.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0504.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0512.htmlhttp://secunia.com/advisories/30627http://secunia.com/advisories/30628http://secunia.com/advisories/30629http://secunia.com/advisories/30630http://secunia.com/advisories/30637http://secunia.com/advisories/30659http://secunia.com/advisories/30664http://secunia.com/advisories/30666http://secunia.com/advisories/30671http://secunia.com/advisories/30715http://secunia.com/advisories/30772http://secunia.com/advisories/30809http://secunia.com/advisories/30843http://secunia.com/advisories/31025http://secunia.com/advisories/31109http://secunia.com/advisories/32099http://secunia.com/advisories/32545http://secunia.com/advisories/33937http://security.gentoo.org/glsa/glsa-200806-07.xmlhttp://securitytracker.com/id?1020246http://sunsolve.sun.com/search/document.do?assetkey=1-26-238686-1http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-249.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0201http://www.debian.org/security/2008/dsa-1595http://www.gentoo.org/security/en/glsa/glsa-200807-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:115http://www.mandriva.com/security/advisories?name=MDVSA-2008:116http://www.mandriva.com/security/advisories?name=MDVSA-2008:179http://www.redhat.com/support/errata/RHSA-2008-0503.htmlhttp://www.securityfocus.com/archive/1/493548/100/0/threadedhttp://www.securityfocus.com/archive/1/493550/100/0/threadedhttp://www.securityfocus.com/bid/29669http://www.ubuntu.com/usn/usn-616-1http://www.vupen.com/english/advisories/2008/1803http://www.vupen.com/english/advisories/2008/1833http://www.vupen.com/english/advisories/2008/1983/referenceshttp://www.vupen.com/english/advisories/2008/3000https://exchange.xforce.ibmcloud.com/vulnerabilities/43016https://issues.rpath.com/browse/RPL-2607https://issues.rpath.com/browse/RPL-2619https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8966ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-1379.diffhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=722http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.freedesktop.org/archives/xorg/2008-June/036026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0502.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0504.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0512.htmlhttp://secunia.com/advisories/30627http://secunia.com/advisories/30628http://secunia.com/advisories/30629http://secunia.com/advisories/30630http://secunia.com/advisories/30637http://secunia.com/advisories/30659http://secunia.com/advisories/30664http://secunia.com/advisories/30666http://secunia.com/advisories/30671http://secunia.com/advisories/30715http://secunia.com/advisories/30772http://secunia.com/advisories/30809http://secunia.com/advisories/30843http://secunia.com/advisories/31025http://secunia.com/advisories/31109http://secunia.com/advisories/32099http://secunia.com/advisories/32545http://secunia.com/advisories/33937http://security.gentoo.org/glsa/glsa-200806-07.xmlhttp://securitytracker.com/id?1020246http://sunsolve.sun.com/search/document.do?assetkey=1-26-238686-1http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-249.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0201http://www.debian.org/security/2008/dsa-1595http://www.gentoo.org/security/en/glsa/glsa-200807-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:115http://www.mandriva.com/security/advisories?name=MDVSA-2008:116http://www.mandriva.com/security/advisories?name=MDVSA-2008:179http://www.redhat.com/support/errata/RHSA-2008-0503.htmlhttp://www.securityfocus.com/archive/1/493548/100/0/threadedhttp://www.securityfocus.com/archive/1/493550/100/0/threadedhttp://www.securityfocus.com/bid/29669http://www.ubuntu.com/usn/usn-616-1http://www.vupen.com/english/advisories/2008/1803http://www.vupen.com/english/advisories/2008/1833http://www.vupen.com/english/advisories/2008/1983/referenceshttp://www.vupen.com/english/advisories/2008/3000
+ 4 more references
2008-06-16
Published