CVE-2010-4819
published 2012-09-05CVE-2010-4819: The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCPINAP
EPSS
0.34%
26.5th percentile
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.9.0.901-1 (bookworm) | xorg-server 2:1.9.0.901-1 (bookworm) |
| x.org | xorg-server | >= 0 < 2:1.9.0.901-1 | 2:1.9.0.901-1 |
| x.org | xorg-server | >= 0 < 2:1.9.0.901-1 | 2:1.9.0.901-1 |
| x.org | xorg-server | >= 0 < 2:1.9.0.901-1 | 2:1.9.0.901-1 |
| x.org | xorg-server | >= 0 < 2:1.9.0.901-1 | 2:1.9.0.901-1 |
| x | x.org-xserver | <= 1.7.7 | — |
| x | x.org-xserver | — | — |
| x | x.org-xserver | — | — |
| x | x.org-xserver | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv3.6LOW
vendor_ubuntu8.5HIGH
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerability
vendor_ubuntu·2011-10-20·CVSS 8.5
CVE-2010-4818 [HIGH] X.Org X server vulnerability
Title: X.Org X server vulnerability
Summary: The X server could be made to crash or run programs as an administrator.
USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was
found on Ubuntu 10.04 LTS that affected GLX support, and USN-1232-2 was
released to temporarily disable the problematic security fix. This update
includes a revised fix for CVE-2010-4818.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server inc
Ubuntu
X.Org X server regression
vendor_ubuntu·2011-10-19·CVSS 8.5
CVE-2010-4818 [HIGH] X.Org X server regression
Title: X.Org X server regression
Summary: USN-1232-1 caused a regression with GLX support.
USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was
found on Ubuntu 10.04 LTS that affected GLX support.
This update temporarily disables the fix for CVE-2010-4818 that introduced
the regression.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2011-10-18·CVSS 8.5
CVE-2011-4029 [HIGH] X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: The X server could be made to crash, run programs as an administrator, or
read arbitrary files.
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly read arbitrary data from
the X server process. This issue only affected Ubuntu 10.04 LTS.
(CVE-2010-4819)
Vladz discovered that the X server
Red Hat
X.org: ProcRenderAddGlyphs input sanitization flaw
vendor_redhat·2010-08-22·CVSS 3.6
CVE-2010-4819 [LOW] X.org: ProcRenderAddGlyphs input sanitization flaw
X.org: ProcRenderAddGlyphs input sanitization flaw
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
Debian
CVE-2010-4819: xorg-server - The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X....
vendor_debian·2010·CVSS 3.6
CVE-2010-4819 [LOW] CVE-2010-4819: xorg-server - The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X....
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
Scope: local
bookworm: resolved (fixed in 2:1.9.0.901-1)
bullseye: resolved (fixed in 2:1.9.0.901-1)
forky: resolved (fixed in 2:1.9.0.901-1)
sid: resolved (fixed in 2:1.9.0.901-1)
trixie: resolved (fixed in 2:1.9.0.901-1)
GHSA
GHSA-3ff3-7r8m-47hr: The ProcRenderAddGlyphs function in the Render extension (render/render
ghsa_unreviewed·2022-05-17
CVE-2010-4819 [LOW] CWE-20 GHSA-3ff3-7r8m-47hr: The ProcRenderAddGlyphs function in the Render extension (render/render
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
OSV
CVE-2010-4819: The ProcRenderAddGlyphs function in the Render extension (render/render
osv·2012-09-05·CVSS 3.6
CVE-2010-4819 [LOW] CVE-2010-4819: The ProcRenderAddGlyphs function in the Render extension (render/render
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
No detection rules found.
No public exploits indexed.
http://aix.software.ibm.com/aix/efixes/security/X_advisory2.aschttp://cgit.freedesktop.org/xorg/xserver/commit/render/render.c?id=5725849a1b427cd4a72b84e57f211edb35838718http://rhn.redhat.com/errata/RHSA-2011-1359.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1360.htmlhttp://securitytracker.com/id?1026149http://www.openwall.com/lists/oss-security/2011/09/22/8http://www.openwall.com/lists/oss-security/2011/09/23/5https://bugs.freedesktop.org/show_bug.cgi?id=28801http://aix.software.ibm.com/aix/efixes/security/X_advisory2.aschttp://cgit.freedesktop.org/xorg/xserver/commit/render/render.c?id=5725849a1b427cd4a72b84e57f211edb35838718http://rhn.redhat.com/errata/RHSA-2011-1359.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1360.htmlhttp://securitytracker.com/id?1026149http://www.openwall.com/lists/oss-security/2011/09/22/8http://www.openwall.com/lists/oss-security/2011/09/23/5https://bugs.freedesktop.org/show_bug.cgi?id=28801
2012-09-05
Published