CVE-2014-8093
published 2014-12-10CVE-2014-8093: Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server)…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.37%
90.3th percentile
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3) __glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5) GetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8) GetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11) __GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize, (14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17) __glXImageSize, or (18) __glXSeparableFilter2DReqSize function, which triggers an out-of-bounds read or write.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.16.2.901-1 (bookworm) | xorg-server 2:1.16.2.901-1 (bookworm) |
| x.org | x11 | — | — |
| x.org | x_server | <= 1.16.2 | — |
| x.org | xfree86 | — | — |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
vendor_redhat·2014-12-09·CVSS 6.5
CVE-2014-8093 [MEDIUM] CWE-190 xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3) __glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5) GetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8) GetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11) __GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize, (14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17) __
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2014-12-09
CVE-2014-8091 X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Ilja van Sprundel discovered a multitude of security issues in the X.Org X
server. An attacker able to connect to an X server, either locally or
remotely, could use these issues to cause the X server to crash or execute
arbitrary code resulting in possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2014-8093: xorg-server - Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window S...
vendor_debian·2014·CVSS 6.5
CVE-2014-8093 [MEDIUM] CVE-2014-8093: xorg-server - Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window S...
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3) __glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5) GetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8) GetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11) __GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize, (14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17) __glXImageSize, or (18) __glXSeparableFilter2DReqSize function, which triggers an out-of-bounds read or wr
GHSA
GHSA-jv75-r474-7vqf: Multiple integer overflows in the GLX extension in XFree86 4
ghsa_unreviewed·2022-05-17
CVE-2014-8093 [MEDIUM] GHSA-jv75-r474-7vqf: Multiple integer overflows in the GLX extension in XFree86 4
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3) __glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5) GetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8) GetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11) __GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize, (14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17) __glXImageSize, or (18) __glXSeparableFilter2DReqSize function, which triggers an out-of-bounds read or wr
OSV
CVE-2014-8093: Multiple integer overflows in the GLX extension in XFree86 4
osv·2014-12-10·CVSS 6.5
CVE-2014-8093 [MEDIUM] CVE-2014-8093: Multiple integer overflows in the GLX extension in XFree86 4
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3) __glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5) GetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8) GetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11) __GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize, (14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17) __glXImageSize, or (18) __glXSeparableFilter2DReqSize function, which triggers an out-of-bounds read or wr
No detection rules found.
No public exploits indexed.
Bugzilla
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
bugzilla·2015-01-11·CVSS 4.3
CVE-2014-8091 [MEDIUM] tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
The Xvnc server (tigervnc-server) and VNC extension for the Xorg server (tigervnc-server-module) are built with xorg-x11-server-source, but have not been rebuilt since the numerous security issues announced in December 2014 (CVE-2014-8091, CVE-2014-8092, CVE-2014-8093, CVE-2014-8094, CVE-2014-8095, CVE-2014-8096, CVE-2014-8097, CVE-2014-8098, CVE-2014-8099, CVE-2014-8100, CVE-2014-8101, CVE-2014-8102, CVE-2014-8103).
Therefore, 1) tigervnc needs to be rebuilt for all supported branches in both Fedora and RHEL, and 2) something needs to be put in place that CVEs in xorg-x11-server also trigger notifications for tigervnc.
Discussion:
(In reply to Yaakov Selkowitz from comment #0)
> 2) something needs to be put in place that CV
Bugzilla
CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8093 [MEDIUM] CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
Various GLX extension functions calls do not check that their calculations for how much memory
is needed to handle the client's request have not overflowed, so can
result in out of bounds reads or writes. These calls all occur only
after a client has successfully authenticated itself.
Affected functions:
__glXDisp_ReadPixels()
__glXDispSwap_ReadPixels()
__glXDisp_GetTexImage()
__glXDispSwap_GetTexImage()
GetSeparableFilter()
GetConvolutionFilter()
GetHistogram()
GetMinmax()
GetColorTable()
Map2Size()
__glXGetAnswerBuffer()
__GLX_GET_ANSWER_BUFFER()
__glXMap1dReqSize()
__glXMap1fReqSize()
__glXMap2dReqSize()
__glXMap2fReqSize()
__glXImageSize()
__glXSeparableFilter2DReqSize
http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/3610http://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71596http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/3610http://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71596http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06
2014-12-10
Published