CVE-2008-2362
published 2008-06-16CVE-2008-2362: Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1)…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.57%
88.1th percentile
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number of bytes to swap in the request data, which triggers heap memory corruption.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.4.1~git20080517-2 (bookworm) | xorg-server 2:1.4.1~git20080517-2 (bookworm) |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080517-2 | 2:1.4.1~git20080517-2 |
| x | x11 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2008-06-13·CVSS 9.0
CVE-2008-2362 [CRITICAL] X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
Multiple flaws were found in the RENDER, RECORD, and Security
extensions of X.org which did not correctly validate function arguments.
An authenticated attacker could send specially crafted requests and gain
root privileges or crash X. (CVE-2008-1377, CVE-2008-2360, CVE-2008-2361,
CVE-2008-2362)
It was discovered that the MIT-SHM extension of X.org did not correctly
validate the location of memory during an image copy. An authenticated
attacker could exploit this to read arbitrary memory locations within X,
exposing sensitive information. (CVE-2008-1379)
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
X.org Render extension input validation flaw causing memory corruption
vendor_redhat·2008-06-11·CVSS 10.0
CVE-2008-2362 [CRITICAL] CWE-20 X.org Render extension input validation flaw causing memory corruption
X.org Render extension input validation flaw causing memory corruption
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number of bytes to swap in the request data, which triggers heap memory corruption.
Debian
CVE-2008-2362: xorg-server - Multiple integer overflows in the Render extension in the X server 1.4 in X.Org ...
vendor_debian·2008·CVSS 10.0
CVE-2008-2362 [CRITICAL] CVE-2008-2362: xorg-server - Multiple integer overflows in the Render extension in the X server 1.4 in X.Org ...
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number of bytes to swap in the request data, which triggers heap memory corruption.
Scope: local
bookworm: resolved (fixed in 2:1.4.1~git20080517-2)
bullseye: resolved (fixed in 2:1.4.1~git20080517-2)
forky: resolved (fixed in 2:1.4.1~git20080517-2)
sid: resolved (fixed in 2:1.4.1~git20080517-2)
trixie: resolved (fixed in 2:1.4.1~git20080517-2)
GHSA
GHSA-5qg4-c78v-h6f8: Multiple integer overflows in the Render extension in the X server 1
ghsa_unreviewed·2022-05-03
CVE-2008-2362 [HIGH] GHSA-5qg4-c78v-h6f8: Multiple integer overflows in the Render extension in the X server 1
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number of bytes to swap in the request data, which triggers heap memory corruption.
OSV
CVE-2008-2362: Multiple integer overflows in the Render extension in the X server 1
osv·2008-06-16·CVSS 10.0
CVE-2008-2362 [CRITICAL] CVE-2008-2362: Multiple integer overflows in the Render extension in the X server 1
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number of bytes to swap in the request data, which triggers heap memory corruption.
No detection rules found.
No public exploits indexed.
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-2362.diffhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=720http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.freedesktop.org/archives/xorg/2008-June/036026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0504.htmlhttp://secunia.com/advisories/30627http://secunia.com/advisories/30630http://secunia.com/advisories/30637http://secunia.com/advisories/30659http://secunia.com/advisories/30664http://secunia.com/advisories/30666http://secunia.com/advisories/30671http://secunia.com/advisories/30715http://secunia.com/advisories/30772http://secunia.com/advisories/30809http://secunia.com/advisories/30843http://secunia.com/advisories/31025http://secunia.com/advisories/31109http://secunia.com/advisories/32099http://secunia.com/advisories/33937http://security.gentoo.org/glsa/glsa-200806-07.xmlhttp://securitytracker.com/id?1020245http://sunsolve.sun.com/search/document.do?assetkey=1-26-238686-1http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-249.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0201http://www.debian.org/security/2008/dsa-1595http://www.gentoo.org/security/en/glsa/glsa-200807-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:116http://www.mandriva.com/security/advisories?name=MDVSA-2008:179http://www.securityfocus.com/archive/1/493548/100/0/threadedhttp://www.securityfocus.com/archive/1/493550/100/0/threadedhttp://www.securityfocus.com/bid/29670http://www.ubuntu.com/usn/usn-616-1http://www.vupen.com/english/advisories/2008/1803http://www.vupen.com/english/advisories/2008/1833http://www.vupen.com/english/advisories/2008/1983/referenceshttps://issues.rpath.com/browse/RPL-2607https://issues.rpath.com/browse/RPL-2619https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11246ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-cve-2008-2362.diffhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=720http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.freedesktop.org/archives/xorg/2008-June/036026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0504.htmlhttp://secunia.com/advisories/30627http://secunia.com/advisories/30630http://secunia.com/advisories/30637http://secunia.com/advisories/30659http://secunia.com/advisories/30664http://secunia.com/advisories/30666http://secunia.com/advisories/30671http://secunia.com/advisories/30715http://secunia.com/advisories/30772http://secunia.com/advisories/30809http://secunia.com/advisories/30843http://secunia.com/advisories/31025http://secunia.com/advisories/31109http://secunia.com/advisories/32099http://secunia.com/advisories/33937http://security.gentoo.org/glsa/glsa-200806-07.xmlhttp://securitytracker.com/id?1020245http://sunsolve.sun.com/search/document.do?assetkey=1-26-238686-1http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-249.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0201http://www.debian.org/security/2008/dsa-1595http://www.gentoo.org/security/en/glsa/glsa-200807-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:116http://www.mandriva.com/security/advisories?name=MDVSA-2008:179http://www.securityfocus.com/archive/1/493548/100/0/threadedhttp://www.securityfocus.com/archive/1/493550/100/0/threadedhttp://www.securityfocus.com/bid/29670http://www.ubuntu.com/usn/usn-616-1http://www.vupen.com/english/advisories/2008/1803http://www.vupen.com/english/advisories/2008/1833http://www.vupen.com/english/advisories/2008/1983/referenceshttps://issues.rpath.com/browse/RPL-2607https://issues.rpath.com/browse/RPL-2619https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11246
2008-06-16
Published