CVE-2008-2361
published 2008-06-16CVE-2008-2361: Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to…
PriorityP424medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
1.64%
73.9th percentile
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.4.1~git20080517-2 (bookworm) | xorg-server 2:1.4.1~git20080517-2 (bookworm) |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| xorg | x11 | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.8MEDIUM
vendor_ubuntu9.0CRITICAL
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2008-06-13·CVSS 9.0
CVE-2008-2362 [CRITICAL] X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
Multiple flaws were found in the RENDER, RECORD, and Security
extensions of X.org which did not correctly validate function arguments.
An authenticated attacker could send specially crafted requests and gain
root privileges or crash X. (CVE-2008-1377, CVE-2008-2360, CVE-2008-2361,
CVE-2008-2362)
It was discovered that the MIT-SHM extension of X.org did not correctly
validate the location of memory during an image copy. An authenticated
attacker could exploit this to read arbitrary memory locations within X,
exposing sensitive information. (CVE-2008-1379)
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
X.org Render extension ProcRenderCreateCursor() crash
vendor_redhat·2008-06-11·CVSS 6.8
CVE-2008-2361 [MEDIUM] X.org Render extension ProcRenderCreateCursor() crash
X.org Render extension ProcRenderCreateCursor() crash
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.
Debian
CVE-2008-2361: xorg-server - Integer overflow in the ProcRenderCreateCursor function in the Render extension ...
vendor_debian·2008·CVSS 6.8
CVE-2008-2361 [MEDIUM] CVE-2008-2361: xorg-server - Integer overflow in the ProcRenderCreateCursor function in the Render extension ...
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.
Scope: local
bookworm: resolved (fixed in 2:1.4.1~git20080517-2)
bullseye: resolved (fixed in 2:1.4.1~git20080517-2)
forky: resolved (fixed in 2:1.4.1~git20080517-2)
sid: resolved (fixed in 2:1.4.1~git20080517-2)
trixie: resolved (fixed in 2:1.4.1~git20080517-2)
GHSA
GHSA-gvwx-pmvm-v23g: Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1
ghsa_unreviewed·2022-05-03
CVE-2008-2361 [MEDIUM] GHSA-gvwx-pmvm-v23g: Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.
OSV
CVE-2008-2361: Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1
osv·2008-06-16·CVSS 6.8
CVE-2008-2361 [MEDIUM] CVE-2008-2361: Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.
No detection rules found.
No public exploits indexed.
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-2361.diffhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=719http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.freedesktop.org/archives/xorg/2008-June/036026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0502.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0504.htmlhttp://secunia.com/advisories/30627http://secunia.com/advisories/30629http://secunia.com/advisories/30630http://secunia.com/advisories/30637http://secunia.com/advisories/30659http://secunia.com/advisories/30664http://secunia.com/advisories/30666http://secunia.com/advisories/30671http://secunia.com/advisories/30715http://secunia.com/advisories/30772http://secunia.com/advisories/30809http://secunia.com/advisories/30843http://secunia.com/advisories/31025http://secunia.com/advisories/31109http://secunia.com/advisories/32099http://secunia.com/advisories/33937http://security.gentoo.org/glsa/glsa-200806-07.xmlhttp://securitytracker.com/id?1020244http://sunsolve.sun.com/search/document.do?assetkey=1-26-238686-1http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-249.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0201http://www.debian.org/security/2008/dsa-1595http://www.gentoo.org/security/en/glsa/glsa-200807-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:115http://www.mandriva.com/security/advisories?name=MDVSA-2008:116http://www.mandriva.com/security/advisories?name=MDVSA-2008:179http://www.redhat.com/support/errata/RHSA-2008-0503.htmlhttp://www.securityfocus.com/archive/1/493548/100/0/threadedhttp://www.securityfocus.com/archive/1/493550/100/0/threadedhttp://www.securityfocus.com/bid/29665http://www.ubuntu.com/usn/usn-616-1http://www.vupen.com/english/advisories/2008/1803http://www.vupen.com/english/advisories/2008/1833http://www.vupen.com/english/advisories/2008/1983/referenceshttps://issues.rpath.com/browse/RPL-2607https://issues.rpath.com/browse/RPL-2619https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8978ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-2361.diffhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=719http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.freedesktop.org/archives/xorg/2008-June/036026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0502.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0504.htmlhttp://secunia.com/advisories/30627http://secunia.com/advisories/30629http://secunia.com/advisories/30630http://secunia.com/advisories/30637http://secunia.com/advisories/30659http://secunia.com/advisories/30664http://secunia.com/advisories/30666http://secunia.com/advisories/30671http://secunia.com/advisories/30715http://secunia.com/advisories/30772http://secunia.com/advisories/30809http://secunia.com/advisories/30843http://secunia.com/advisories/31025http://secunia.com/advisories/31109http://secunia.com/advisories/32099http://secunia.com/advisories/33937http://security.gentoo.org/glsa/glsa-200806-07.xmlhttp://securitytracker.com/id?1020244http://sunsolve.sun.com/search/document.do?assetkey=1-26-238686-1http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-249.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0201http://www.debian.org/security/2008/dsa-1595http://www.gentoo.org/security/en/glsa/glsa-200807-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:115http://www.mandriva.com/security/advisories?name=MDVSA-2008:116http://www.mandriva.com/security/advisories?name=MDVSA-2008:179http://www.redhat.com/support/errata/RHSA-2008-0503.htmlhttp://www.securityfocus.com/archive/1/493548/100/0/threadedhttp://www.securityfocus.com/archive/1/493550/100/0/threadedhttp://www.securityfocus.com/bid/29665http://www.ubuntu.com/usn/usn-616-1http://www.vupen.com/english/advisories/2008/1803http://www.vupen.com/english/advisories/2008/1833http://www.vupen.com/english/advisories/2008/1983/referenceshttps://issues.rpath.com/browse/RPL-2607https://issues.rpath.com/browse/RPL-2619https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8978
2008-06-16
Published