CVE-2014-8097
published 2014-12-10CVE-2014-8097: The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated…
PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.37%
90.3th percentile
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcDbeSwapBuffers or (2) SProcDbeSwapBuffers function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.16.2.901-1 (bookworm) | xorg-server 2:1.16.2.901-1 (bookworm) |
| x.org | x11 | — | — |
| x.org | x_server | <= 1.16.2.99.901 | — |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2014-12-09
CVE-2014-8091 X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Ilja van Sprundel discovered a multitude of security issues in the X.Org X
server. An attacker able to connect to an X server, either locally or
remotely, could use these issues to cause the X server to crash or execute
arbitrary code resulting in possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: out of bounds access due to not validating length or offset values in DBE extension
vendor_redhat·2014-12-09·CVSS 6.5
CVE-2014-8097 [MEDIUM] CWE-190 xorg-x11-server: out of bounds access due to not validating length or offset values in DBE extension
xorg-x11-server: out of bounds access due to not validating length or offset values in DBE extension
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcDbeSwapBuffers or (2) SProcDbeSwapBuffers function.
Multiple out-of-bounds access flaws were found in the way the X.Org server calculated memory requirements for certain requests. A malicious, authenticated client could use either of these flaws to crash the X.Org server, or leak memory contents to the client.
Debian
CVE-2014-8097: xorg-server - The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Serv...
vendor_debian·2014·CVSS 6.5
CVE-2014-8097 [MEDIUM] CVE-2014-8097: xorg-server - The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Serv...
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcDbeSwapBuffers or (2) SProcDbeSwapBuffers function.
Scope: local
bookworm: resolved (fixed in 2:1.16.2.901-1)
bullseye: resolved (fixed in 2:1.16.2.901-1)
forky: resolved (fixed in 2:1.16.2.901-1)
sid: resolved (fixed in 2:1.16.2.901-1)
trixie: resolved (fixed in 2:1.16.2.901-1)
GHSA
GHSA-5v63-4r2j-93hp: The DBE extension in X
ghsa_unreviewed·2022-05-17
CVE-2014-8097 [MEDIUM] CWE-119 GHSA-5v63-4r2j-93hp: The DBE extension in X
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcDbeSwapBuffers or (2) SProcDbeSwapBuffers function.
OSV
CVE-2014-8097: The DBE extension in X
osv·2014-12-10·CVSS 6.5
CVE-2014-8097 [MEDIUM] CVE-2014-8097: The DBE extension in X
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcDbeSwapBuffers or (2) SProcDbeSwapBuffers function.
No detection rules found.
No public exploits indexed.
Bugzilla
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
bugzilla·2015-01-11·CVSS 4.3
CVE-2014-8091 [MEDIUM] tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
The Xvnc server (tigervnc-server) and VNC extension for the Xorg server (tigervnc-server-module) are built with xorg-x11-server-source, but have not been rebuilt since the numerous security issues announced in December 2014 (CVE-2014-8091, CVE-2014-8092, CVE-2014-8093, CVE-2014-8094, CVE-2014-8095, CVE-2014-8096, CVE-2014-8097, CVE-2014-8098, CVE-2014-8099, CVE-2014-8100, CVE-2014-8101, CVE-2014-8102, CVE-2014-8103).
Therefore, 1) tigervnc needs to be rebuilt for all supported branches in both Fedora and RHEL, and 2) something needs to be put in place that CVEs in xorg-x11-server also trigger notifications for tigervnc.
Discussion:
(In reply to Yaakov Selkowitz from comment #0)
> 2) something needs to be put in place that CV
Bugzilla
CVE-2014-8097 xorg-x11-server: out of bounds access due to not validating length or offset values in DBE extension
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8097 [MEDIUM] CVE-2014-8097 xorg-x11-server: out of bounds access due to not validating length or offset values in DBE extension
CVE-2014-8097 xorg-x11-server: out of bounds access due to not validating length or offset values in DBE extension
ProcDbeSwapBuffers() and SProcDbeSwapBuffers() DBE extension calls do not check that the lengths and/or indexes sent by the
client are within the bounds specified by the caller or the bounds of
the memory allocated to hold the request read from the client, so could
read or write past the bounds of allocated memory while processing the
request. These calls all occur only after a client has successfully
authenticated itself.
Introduced in X11R6.1 (1996).
Discussion:
Created attachment 962137
0007-dbe_unvalidated_lengths_in_DbeSwapBuffers_calls_CVE-2014-8097.patch
---
Integer overflow causing OOB read and crash. Could also result in OOB data being sent to the client, result
http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71604http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71604http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06
2014-12-10
Published