CVE-2014-8101
published 2014-12-10CVE-2014-8101: The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.37%
90.3th percentile
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcRRQueryVersion, (2) SProcRRGetScreenInfo, (3) SProcRRSelectInput, or (4) SProcRRConfigureOutputProperty function.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.16.2.901-1 (bookworm) | xorg-server 2:1.16.2.901-1 (bookworm) |
| x.org | x11 | — | — |
| x.org | x_server | <= 1.16.2.99.901 | — |
| x.org | xfree86 | — | — |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.16.2.901-1 | 2:1.16.2.901-1 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2014-12-09
CVE-2014-8091 X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Ilja van Sprundel discovered a multitude of security issues in the X.Org X
server. An attacker able to connect to an X server, either locally or
remotely, could use these issues to cause the X server to crash or execute
arbitrary code resulting in possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: out of bounds access due to not validating length or offset values in RandR extension
vendor_redhat·2014-12-09·CVSS 6.5
CVE-2014-8101 [MEDIUM] CWE-20 xorg-x11-server: out of bounds access due to not validating length or offset values in RandR extension
xorg-x11-server: out of bounds access due to not validating length or offset values in RandR extension
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcRRQueryVersion, (2) SProcRRGetScreenInfo, (3) SProcRRSelectInput, or (4) SProcRRConfigureOutputProperty function.
Multiple out-of-bounds access flaws were found in the way the X.Org server calculated memory requirements for certain requests. A malicious, authenticated client could use either of these flaws to crash the X.Org server.
Debian
CVE-2014-8101: xorg-server - The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6...
vendor_debian·2014·CVSS 6.5
CVE-2014-8101 [MEDIUM] CVE-2014-8101: xorg-server - The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6...
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcRRQueryVersion, (2) SProcRRGetScreenInfo, (3) SProcRRSelectInput, or (4) SProcRRConfigureOutputProperty function.
Scope: local
bookworm: resolved (fixed in 2:1.16.2.901-1)
bullseye: resolved (fixed in 2:1.16.2.901-1)
forky: resolved (fixed in 2:1.16.2.901-1)
sid: resolved (fixed in 2:1.16.2.901-1)
trixie: resolved (fixed in 2:1.16.2.901-1)
GHSA
GHSA-5vpf-mx7j-6j95: The RandR extension in XFree86 4
ghsa_unreviewed·2022-05-17
CVE-2014-8101 [MEDIUM] CWE-119 GHSA-5vpf-mx7j-6j95: The RandR extension in XFree86 4
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcRRQueryVersion, (2) SProcRRGetScreenInfo, (3) SProcRRSelectInput, or (4) SProcRRConfigureOutputProperty function.
OSV
CVE-2014-8101: The RandR extension in XFree86 4
osv·2014-12-10·CVSS 6.5
CVE-2014-8101 [MEDIUM] CVE-2014-8101: The RandR extension in XFree86 4
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcRRQueryVersion, (2) SProcRRGetScreenInfo, (3) SProcRRSelectInput, or (4) SProcRRConfigureOutputProperty function.
No detection rules found.
No public exploits indexed.
Bugzilla
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
bugzilla·2015-01-11·CVSS 4.3
CVE-2014-8091 [MEDIUM] tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
tigervnc requires rebuild after Dec-2014 xorg-x11-server CVEs
The Xvnc server (tigervnc-server) and VNC extension for the Xorg server (tigervnc-server-module) are built with xorg-x11-server-source, but have not been rebuilt since the numerous security issues announced in December 2014 (CVE-2014-8091, CVE-2014-8092, CVE-2014-8093, CVE-2014-8094, CVE-2014-8095, CVE-2014-8096, CVE-2014-8097, CVE-2014-8098, CVE-2014-8099, CVE-2014-8100, CVE-2014-8101, CVE-2014-8102, CVE-2014-8103).
Therefore, 1) tigervnc needs to be rebuilt for all supported branches in both Fedora and RHEL, and 2) something needs to be put in place that CVEs in xorg-x11-server also trigger notifications for tigervnc.
Discussion:
(In reply to Yaakov Selkowitz from comment #0)
> 2) something needs to be put in place that CV
Bugzilla
CVE-2014-8101 xorg-x11-server: out of bounds access due to not validating length or offset values in RandR extension
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8101 [MEDIUM] CVE-2014-8101 xorg-x11-server: out of bounds access due to not validating length or offset values in RandR extension
CVE-2014-8101 xorg-x11-server: out of bounds access due to not validating length or offset values in RandR extension
Various RandR extension calls do not check that the lengths and/or indexes sent by the
client are within the bounds specified by the caller or the bounds of
the memory allocated to hold the request read from the client, so could
read or write past the bounds of allocated memory while processing the
request. These calls all occur only after a client has successfully
authenticated itself.
Discussion:
Created attachment 962152
0013-randr_unvalidated_lengths_in_RandR_extension_swapped_procs_CVE-2014-8101.patch
---
OOb read via client request causing X server crash.
---
External References:
http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/
---
This issue h
http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71605http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06http://advisories.mageia.org/MGASA-2014-0532.htmlhttp://secunia.com/advisories/61947http://secunia.com/advisories/62292http://www.debian.org/security/2014/dsa-3095http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/71605http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/https://security.gentoo.org/glsa/201504-06
2014-12-10
Published