CVE-2014-8092
published 2014-12-10CVE-2014-8092: Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.37%
90.3th percentile
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which triggers an out-of-bounds read or write.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.16.2.901-1 (bookworm) | xorg-server 2:1.16.2.901-1 (bookworm) |
| x.org | x11 | — | — |
| x.org | x_server | <= 1.16.2.99.901 | — |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2014-12-09
CVE-2014-8091 X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Ilja van Sprundel discovered a multitude of security issues in the X.Org X
server. An attacker able to connect to an X server, either locally or
remotely, could use these issues to cause the X server to crash or execute
arbitrary code resulting in possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
vendor_redhat·2014-12-09·CVSS 6.5
CVE-2014-8092 [MEDIUM] CWE-190 xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which triggers an out-of-bounds read or write.
Multiple integer overflow flaws were found in the way the X.Org server calculated memory requirements for certain X11 core protocol requests. A malicious, authenticated client could use either of these flaws to crash the X.Org server or, potentially, execute arbitrary code with root privil
Debian
CVE-2014-8092: xorg-server - Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.O...
vendor_debian·2014·CVSS 6.5
CVE-2014-8092 [MEDIUM] CVE-2014-8092: xorg-server - Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.O...
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which triggers an out-of-bounds read or write.
Scope: local
bookworm: resolved (fixed in 2:1.16.2.901-1)
bullseye: resolved (fixed in 2:1.16.2.901-1)
forky: resolved (fixed in 2:1.16.2.901-1)
sid: resolved (fixed in 2:1.16.2.901-1)
trixie: resolved (fixed in 2:1.16.2.901-1)
GHSA
GHSA-5xcf-4m43-c4p9: Multiple integer overflows in X
ghsa_unreviewed·2022-05-17
CVE-2014-8092 [MEDIUM] GHSA-5xcf-4m43-c4p9: Multiple integer overflows in X
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which triggers an out-of-bounds read or write.
OSV
CVE-2014-8092: Multiple integer overflows in X
osv·2014-12-10·CVSS 6.5
CVE-2014-8092 [MEDIUM] CVE-2014-8092: Multiple integer overflows in X
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which triggers an out-of-bounds read or write.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3418 xorg-x11-server: divide-by-zero when checking image dimensions
bugzilla·2015-04-28·CVSS 6.5
CVE-2015-3418 [MEDIUM] CVE-2015-3418 xorg-x11-server: divide-by-zero when checking image dimensions
CVE-2015-3418 xorg-x11-server: divide-by-zero when checking image dimensions
A divide-by-zero flaw was found in the way the X.Org server checked the dimensions of certain images. An attacker may be able to crash the X.Org server by tricking a suitable X application into displaying a specially crafted image file.
This was introduced by the fix for the CVE-2014-8092 issue.
Upstream patch:
http://cgit.freedesktop.org/xorg/xserver/commit/?id=dc777c346d5d452a53b13b917c45f6a1bad2f20b
Discussion:
Created xorg-x11-server tracking bugs for this issue:
Affects: fedora-all [bug 1216022]
---
Although a malicious authenticated client could exploit this flaw to crash the X.Org server, this does not really cross any security boundaries, as X.Org provides other, intended mechanisms with the same
Bugzilla
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
bugzilla·2015-01-11·CVSS 4.3
CVE-2014-8091 [MEDIUM] tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
The Xvnc server (tigervnc-server) and VNC extension for the Xorg server (tigervnc-server-module) are built with xorg-x11-server-source, but have not been rebuilt since the numerous security issues announced in December 2014 (CVE-2014-8091, CVE-2014-8092, CVE-2014-8093, CVE-2014-8094, CVE-2014-8095, CVE-2014-8096, CVE-2014-8097, CVE-2014-8098, CVE-2014-8099, CVE-2014-8100, CVE-2014-8101, CVE-2014-8102, CVE-2014-8103).
Therefore, 1) tigervnc needs to be rebuilt for all supported branches in both Fedora and RHEL, and 2) something needs to be put in place that CVEs in xorg-x11-server also trigger notifications for tigervnc.
Discussion:
(In reply to Yaakov Selkowitz from comment #0)
> 2) something needs to be put in place that CV
Bugzilla
CVE-2014-8092 xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8092 [MEDIUM] CVE-2014-8092 xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
CVE-2014-8092 xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
ProcPutImage(), GetHosts(), RegionSizeof(), REQUEST_FIXED_SIZE() calls do not check that their calculations for how much memory
is needed to handle the client's request have not overflowed, so can
result in out of bounds reads or writes. These calls all occur only
after a client has successfully authenticated itself.
Introduced in X11R1 (1987).
Discussion:
Created attachment 962113
0002-dix_integer_overflow_in_ProcPutImage_CVE-2014-8092_1-4.patch
---
Created attachment 962114
0003-dix_integer_overflow_in_GetHosts_CVE-2014-8092_2-4.patch
---
Created attachment 962115
0004-dix_integer_overflow_in_RegionSizeof_CVE-2014-8092_3-4.patch
---
Created attachment 962116
http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71595http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71595http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06
2014-12-10
Published