CVE-2014-8100
published 2014-12-10CVE-2014-8100: The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote…
PriorityP336medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.37%
90.3th percentile
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SProcRenderQueryVersion, (3) SProcRenderQueryPictFormats, (4) SProcRenderQueryPictIndexValues, (5) SProcRenderCreatePicture, (6) SProcRenderChangePicture, (7) SProcRenderSetPictureClipRectangles, (8) SProcRenderFreePicture, (9) SProcRenderComposite, (10) SProcRenderScale, (11) SProcRenderCreateGlyphSet, (12) SProcRenderReferenceGlyphSet, (13) SProcRenderFreeGlyphSet, (14) SProcRenderFreeGlyphs, or (15) SProcRenderCompositeGlyphs function.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.16.2.901-1 (bookworm) | xorg-server 2:1.16.2.901-1 (bookworm) |
| x.org | x11 | — | — |
| x.org | x_server | <= 1.16.2.99.901 | — |
| x.org | xfree86 | — | — |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2014-12-09
CVE-2014-8091 X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Ilja van Sprundel discovered a multitude of security issues in the X.Org X
server. An attacker able to connect to an X server, either locally or
remotely, could use these issues to cause the X server to crash or execute
arbitrary code resulting in possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: out of bounds access due to not validating length or offset values in Render extension
vendor_redhat·2014-12-09·CVSS 6.5
CVE-2014-8100 [MEDIUM] CWE-20 xorg-x11-server: out of bounds access due to not validating length or offset values in Render extension
xorg-x11-server: out of bounds access due to not validating length or offset values in Render extension
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SProcRenderQueryVersion, (3) SProcRenderQueryPictFormats, (4) SProcRenderQueryPictIndexValues, (5) SProcRenderCreatePicture, (6) SProcRenderChangePicture, (7) SProcRenderSetPictureClipRectangles, (8) SProcRenderFreePicture, (9) SProcRenderComposite, (10) SProcRenderScale, (11) SProcRenderCreateGlyphSet, (12) SProcRenderReferenceGlyphSet, (13) S
Debian
CVE-2014-8100: xorg-server - The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R...
vendor_debian·2014·CVSS 6.5
CVE-2014-8100 [MEDIUM] CVE-2014-8100: xorg-server - The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R...
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SProcRenderQueryVersion, (3) SProcRenderQueryPictFormats, (4) SProcRenderQueryPictIndexValues, (5) SProcRenderCreatePicture, (6) SProcRenderChangePicture, (7) SProcRenderSetPictureClipRectangles, (8) SProcRenderFreePicture, (9) SProcRenderComposite, (10) SProcRenderScale, (11) SProcRenderCreateGlyphSet, (12) SProcRenderReferenceGlyphSet, (13) SProcRenderFreeGlyphSet, (14) SProcRenderFreeGlyphs, or (15) SProcRenderCompositeGlyphs function.
Scope: l
GHSA
GHSA-829w-46r8-7v9x: The Render extension in XFree86 4
ghsa_unreviewed·2022-05-17
CVE-2014-8100 [MEDIUM] CWE-119 GHSA-829w-46r8-7v9x: The Render extension in XFree86 4
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SProcRenderQueryVersion, (3) SProcRenderQueryPictFormats, (4) SProcRenderQueryPictIndexValues, (5) SProcRenderCreatePicture, (6) SProcRenderChangePicture, (7) SProcRenderSetPictureClipRectangles, (8) SProcRenderFreePicture, (9) SProcRenderComposite, (10) SProcRenderScale, (11) SProcRenderCreateGlyphSet, (12) SProcRenderReferenceGlyphSet, (13) SProcRenderFreeGlyphSet, (14) SProcRenderFreeGlyphs, or (15) SProcRenderCompositeGlyphs function.
OSV
CVE-2014-8100: The Render extension in XFree86 4
osv·2014-12-10·CVSS 6.5
CVE-2014-8100 [MEDIUM] CVE-2014-8100: The Render extension in XFree86 4
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SProcRenderQueryVersion, (3) SProcRenderQueryPictFormats, (4) SProcRenderQueryPictIndexValues, (5) SProcRenderCreatePicture, (6) SProcRenderChangePicture, (7) SProcRenderSetPictureClipRectangles, (8) SProcRenderFreePicture, (9) SProcRenderComposite, (10) SProcRenderScale, (11) SProcRenderCreateGlyphSet, (12) SProcRenderReferenceGlyphSet, (13) SProcRenderFreeGlyphSet, (14) SProcRenderFreeGlyphs, or (15) SProcRenderCompositeGlyphs function.
No detection rules found.
No public exploits indexed.
Bugzilla
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
bugzilla·2015-01-11·CVSS 4.3
CVE-2014-8091 [MEDIUM] tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
The Xvnc server (tigervnc-server) and VNC extension for the Xorg server (tigervnc-server-module) are built with xorg-x11-server-source, but have not been rebuilt since the numerous security issues announced in December 2014 (CVE-2014-8091, CVE-2014-8092, CVE-2014-8093, CVE-2014-8094, CVE-2014-8095, CVE-2014-8096, CVE-2014-8097, CVE-2014-8098, CVE-2014-8099, CVE-2014-8100, CVE-2014-8101, CVE-2014-8102, CVE-2014-8103).
Therefore, 1) tigervnc needs to be rebuilt for all supported branches in both Fedora and RHEL, and 2) something needs to be put in place that CVEs in xorg-x11-server also trigger notifications for tigervnc.
Discussion:
(In reply to Yaakov Selkowitz from comment #0)
> 2) something needs to be put in place that CV
Bugzilla
CVE-2014-8100 xorg-x11-server: out of bounds access due to not validating length or offset values in Render extension
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8100 [MEDIUM] CVE-2014-8100 xorg-x11-server: out of bounds access due to not validating length or offset values in Render extension
CVE-2014-8100 xorg-x11-server: out of bounds access due to not validating length or offset values in Render extension
Various Render extension calls do not check that the lengths and/or indexes sent by the
client are within the bounds specified by the caller or the bounds of
the memory allocated to hold the request read from the client, so could
read or write past the bounds of allocated memory while processing the
request. These calls all occur only after a client has successfully
authenticated itself.
Affected functions: ProcRenderQueryVersion(), SProcRenderQueryVersion(),
SProcRenderQueryPictFormats(), SProcRenderQueryPictIndexValues(),
SProcRenderCreatePicture(), SProcRenderChangePicture(),
SProcRenderSetPictureClipRectangles(), SProcRenderFreePicture(),
SProcRenderComposite(), SProc
http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71602http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71602http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06
2014-12-10
Published