iDefense Security Advisory – Local exploitation of a memory corruption vulnerability in the “ProcDbeGetVisualInfo” function in the X.Org and XFree86 X server could allow an attacker to execute arbitrary code with privileges of the X server, typically root. This vulnerability specifically lies within the DBE extension. Insufficient input validation exists when allocating memory for data structures. By sending a specially crafted X protocol request to the DBE extension, an attacker can cause an exploitable memory corruption condition. iDefense has confirmed the existence of this vulnerability in the X.Org server version 7.1-1.1.0. Previous versions may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53576/01.09.07-5.txt
Source: https://packetstormsecurity.com/files/53576/iDEFENSE-Security-Advisory-2007-01-09.5.html

