iDefense Security Advisory 06.11.08 – Local exploitation of an information disclosure vulnerability in the X.Org X server, as included in various vendors’ operating system distributions, could allow an attacker to gain access to sensitive information stored in server memory. The vulnerability exists when creating a Pixmap in the fbShmPutImage() function. The width and height of the Pixmap, which are controlled by the user, are not properly validated to ensure that the Pixmap they define are within the bounds of the shared memory segment. This allows an attacker to read arbitrary areas of memory in the X server process. iDefense has confirmed the existence of this vulnerability in X server 1.4 included with X.org X11R7.3, with all patches as of 03/01/08 applied. Previous versions may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/67212/06.11.08-5.txt
Source: https://packetstormsecurity.com/files/67212/iDEFENSE-Security-Advisory-2008-06-11.5.html