CVE-2014-8094
published 2014-12-10CVE-2014-8094: Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3…
PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.30%
90.1th percentile
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
Affected
163 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:1.16.2.901-1 (bookworm) | xorg-server 2:1.16.2.901-1 (bookworm) |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
| x.org | x_server | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2014-12-09
CVE-2014-8091 X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Ilja van Sprundel discovered a multitude of security issues in the X.Org X
server. An attacker able to connect to an X server, either locally or
remotely, could use these issues to cause the X server to crash or execute
arbitrary code resulting in possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: integer overflow in DRI2 extension function ProcDRI2GetBuffers()
vendor_redhat·2014-12-09·CVSS 6.5
CVE-2014-8094 [MEDIUM] CWE-190 xorg-x11-server: integer overflow in DRI2 extension function ProcDRI2GetBuffers()
xorg-x11-server: integer overflow in DRI2 extension function ProcDRI2GetBuffers()
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
An integer overflow flaw was found in the way the X.Org server calculated memory requirements for certain DRI2 extension requests. A malicious, authenticated client could use this flaw to crash the X.Org server.
Package: xorg-x11-server (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-8094: xorg-server - Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.O...
vendor_debian·2014·CVSS 6.5
CVE-2014-8094 [MEDIUM] CVE-2014-8094: xorg-server - Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.O...
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
Scope: local
bookworm: resolved (fixed in 2:1.16.2.901-1)
bullseye: resolved (fixed in 2:1.16.2.901-1)
forky: resolved (fixed in 2:1.16.2.901-1)
sid: resolved (fixed in 2:1.16.2.901-1)
trixie: resolved (fixed in 2:1.16.2.901-1)
GHSA
GHSA-qmxm-339w-x3r6: Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X
ghsa_unreviewed·2022-05-17
CVE-2014-8094 [MEDIUM] CWE-190 GHSA-qmxm-339w-x3r6: Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
OSV
CVE-2014-8094: Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X
osv·2014-12-10·CVSS 6.5
CVE-2014-8094 [MEDIUM] CVE-2014-8094: Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
No detection rules found.
No public exploits indexed.
Bugzilla
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
bugzilla·2015-01-11·CVSS 4.3
CVE-2014-8091 [MEDIUM] tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
The Xvnc server (tigervnc-server) and VNC extension for the Xorg server (tigervnc-server-module) are built with xorg-x11-server-source, but have not been rebuilt since the numerous security issues announced in December 2014 (CVE-2014-8091, CVE-2014-8092, CVE-2014-8093, CVE-2014-8094, CVE-2014-8095, CVE-2014-8096, CVE-2014-8097, CVE-2014-8098, CVE-2014-8099, CVE-2014-8100, CVE-2014-8101, CVE-2014-8102, CVE-2014-8103).
Therefore, 1) tigervnc needs to be rebuilt for all supported branches in both Fedora and RHEL, and 2) something needs to be put in place that CVEs in xorg-x11-server also trigger notifications for tigervnc.
Discussion:
(In reply to Yaakov Selkowitz from comment #0)
> 2) something needs to be put in place that CV
Bugzilla
CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8093 [MEDIUM] CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests when calculating memory needs for requests
Various GLX extension functions calls do not check that their calculations for how much memory
is needed to handle the client's request have not overflowed, so can
result in out of bounds reads or writes. These calls all occur only
after a client has successfully authenticated itself.
Affected functions:
__glXDisp_ReadPixels()
__glXDispSwap_ReadPixels()
__glXDisp_GetTexImage()
__glXDispSwap_GetTexImage()
GetSeparableFilter()
GetConvolutionFilter()
GetHistogram()
GetMinmax()
GetColorTable()
Map2Size()
__glXGetAnswerBuffer()
__GLX_GET_ANSWER_BUFFER()
__glXMap1dReqSize()
__glXMap1fReqSize()
__glXMap2dReqSize()
__glXMap2fReqSize()
__glXImageSize()
__glXSeparableFilter2DReqSize
Bugzilla
CVE-2014-8094 xorg-x11-server: integer overflow in DRI2 extension function ProcDRI2GetBuffers()
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8094 [MEDIUM] CVE-2014-8094 xorg-x11-server: integer overflow in DRI2 extension function ProcDRI2GetBuffers()
CVE-2014-8094 xorg-x11-server: integer overflow in DRI2 extension function ProcDRI2GetBuffers()
ProcDRI2GetBuffers() function call do not check that its calculations for how much memory
is needed to handle the client's request have not overflowed, so can
result in out of bounds reads or writes. These calls all occur only
after a client has successfully authenticated itself.
Introduced in xorg-server-1.7.0 (2009).
Discussion:
Created attachment 962135
0006-dri2_integer_overflow_in_ProcDRI2GetBuffers_CVE-2014-8094.patch
---
Authenticated client can cause integer overflow on the server which later results in OOB read and consequent crash.
---
External References:
http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/
---
This issue has been addressed in the following produ
http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/71601http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/71601http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06
2014-12-10
Published