SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#102441

Multiple X servers fail to properly allocate memory for large pixmaps

Overview

Multiple X Window System servers contain a pixmap memory allocation flaw that may allow local users to execute code with elevated privileges.

I. Description

Multiple X Window System server applications share code that may contain a flaw in the memory allocation for large pixmaps. The affected products include the X.Org and XFree86 X server applications, possibly among others.

An integer overflow condition may result in a memory allocation request returning an allocated region that is incorrectly sized. The client may then be able to use the XDrawPoint() and XGetImage() functions to read and write to arbitrary locations in the X server's address space.

II. Impact

A malicious local authenticated attacker may be able to execute arbitrary code with the privileges of the X server.

III. Solution

Apply an update

Contact your vendor for updates, fixes, and workarounds.

Systems Affected

VendorStatusDate Updated
Apple Computer, Inc.Unknown7-Sep-2005
Cray Inc.Unknown7-Sep-2005
Debian LinuxVulnerable19-Sep-2005
EMC, Inc. (formerly Data General Corporation)Unknown7-Sep-2005
Engarde Secure LinuxUnknown7-Sep-2005
F5 Networks, Inc.Unknown7-Sep-2005
Fedora ProjectVulnerable19-Sep-2005
FreeBSD, Inc.Unknown7-Sep-2005
FujitsuUnknown7-Sep-2005
Gentoo LinuxVulnerable19-Sep-2005
Hewlett-Packard CompanyUnknown7-Sep-2005
HitachiNot Vulnerable19-Sep-2005
IBM CorporationUnknown7-Sep-2005
IBM Corporation (zseries)Unknown7-Sep-2005
IBM eServerUnknown7-Sep-2005
Immunix Communications, Inc.Unknown7-Sep-2005
Ingrian Networks, Inc. Unknown7-Sep-2005
Juniper Networks, Inc.Unknown7-Sep-2005
Mandriva, Inc.Unknown7-Sep-2005
Mandriva, Inc.Vulnerable19-Sep-2005
Microsoft CorporationUnknown7-Sep-2005
MontaVista Software, Inc.Unknown7-Sep-2005
NEC CorporationUnknown7-Sep-2005
NetBSDUnknown7-Sep-2005
Novell, Inc. Unknown7-Sep-2005
OpenBSDUnknown7-Sep-2005
Openwall GNU/*/LinuxUnknown7-Sep-2005
QNX, Software Systems, Inc.Unknown7-Sep-2005
Red Hat, Inc.Vulnerable29-Sep-2005
Sequent Computer Systems, Inc.Unknown7-Sep-2005
Silicon Graphics, Inc.Unknown7-Sep-2005
Slackware Linux Inc.Vulnerable26-Sep-2005
Sony CorporationUnknown7-Sep-2005
Sun Microsystems, Inc.Unknown7-Sep-2005
SUSE LinuxVulnerable26-Sep-2005
The SCO Group (SCO Linux)Unknown7-Sep-2005
The SCO Group (SCO Unix)Unknown7-Sep-2005
Trustix Secure LinuxVulnerable19-Sep-2005
TurbolinuxUnknown7-Sep-2005
UnisysUnknown7-Sep-2005
Wind River Systems, Inc.Unknown7-Sep-2005
xFree86 (distributor of free implementations of X)Unknown3-Nov-2005

References


https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166859
https://bugs.freedesktop.org/show_bug.cgi?id=594
http://secunia.com/advisories/16777/
http://secunia.com/advisories/16790/
https://rhn.redhat.com/errata/RHSA-2005-329.html

Credit

Thanks to Luke Hutchison and Søren Sandmann Pedersen for reporting this vulnerability.

This document was written by Ken MacInnis.

Other Information

Date Public09/12/2005
Date First Published09/13/2005 02:17:26 PM
Date Last Updated11/03/2005
CERT Advisory 
CVE NameCAN-2005-2495
US-CERT Technical Alerts 
Metric7.42
Document Revision29

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader