Back

HIGH

xfree86: integer overflow in EVI extension

Published Jan 18, 2008

Description

Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (73)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 18, 2008
Updated Aug 7, 2024
Reserved Dec 18, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jan 17, 2008