iDefense Security Advisory 01.17.08 – Local exploitation of multiple memory corruption vulnerabilities in the X.Org X server, as included in various vendors’ operating system distributions, allows attackers to execute arbitrary code with the privileges of the X server, typically root. Vulnerable code exists within multiple functions in the XInput extension. By sending specially crafted X11 requests, an attacker is able to corrupt heap memory located after their request data. This results in a potentially exploitable condition. Defense has confirmed the existence of these vulnerabilities in X.Org X11 version R7.3. Previous versions may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/62758/01.17.08-1.txt
Source: https://packetstormsecurity.com/files/62758/iDEFENSE-Security-Advisory-2008-01-17.1.html

