Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-04-03.5

iDefense Security Advisory 04.03.07 – Local exploitation of a memory corruption vulnerability in the multiple vendor’s X server implementations could allow an attacker to execute arbitrary code with elevated privileges. The XC-MISC extension is used by the X Server to manage resource IDs. It is built in to the X server by default. The vulnerability exists in the ProcXCMiscGetXIDList() function in the XC-MISC extension. This request is used to determine what resource IDs are available for use. Inside this function, the ALLOCATE_LOCAL() macro is used. This macro allocates memory on the stack or heap depending on the availability of the alloca() function. If alloca() is available, the stack is used, other wise the heap is used. Due to insufficient input validation, it is possible to cause memory corruption by passing specially crafted values to the ProcXCMiscGetXIDList() handler function. iDefense has confirmed the existence of this vulnerability in the X.org server version 7.1-1.1.0. Previous versions may also be affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55596/04.03.07-5.txt

Source: https://packetstormsecurity.com/files/55596/iDEFENSE-Security-Advisory-2007-04-03.5.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534