HIGH
X.org: multiple GLX input sanitization flaws
Published Sep 5, 2012
8.5
HIGHCVSS 2.0
EPSS 5.35%
Description
The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via (1) a crafted request that triggers a client swap in glx/glxcmdsswap.c; or (2) a crafted length or (3) a negative value in the screen field in a request to glx/glxcmds.c.
Affected products
No data.
No data.
Red Hat Enterprise Linux 4
xorg-x11-0:6.8.2-1.EL.70
Fixed · RHSA-2011:1360
Red Hat Enterprise Linux 5
xorg-x11-server-0:1.1.1-48.76.el5_7.5
Fixed · RHSA-2011:1359
Red Hat Enterprise Linux 6
xorg-x11-server-0:1.7.7-29.el6_1.2
Fixed · RHSA-2011:1359
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | xorg-x11-0:6.8.2-1.EL.70 | Fixed | RHSA-2011:1360 |
| Red Hat Enterprise Linux 5 | xorg-x11-server-0:1.1.1-48.76.el5_7.5 | Fixed | RHSA-2011:1359 |
| Red Hat Enterprise Linux 6 | xorg-x11-server-0:1.7.7-29.el6_1.2 | Fixed | RHSA-2011:1359 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://cgit.freedesktop.org/xorg/xserver/commit?id=3f0d3f4d97bce75c1828635c322b6560a45a037f x_refsource_CONFIRM
- http://cgit.freedesktop.org/xorg/xserver/commit?id=6c69235a9dfc52e4b4e47630ff4bab1a820eb543 x_refsource_CONFIRM
- http://cgit.freedesktop.org/xorg/xserver/commit?id=ec9c97c6bf70b523bc500bd3adf62176f1bb33a4 x_refsource_CONFIRMExploitPatch
- http://rhn.redhat.com/errata/RHSA-2011-1359.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2011-1360.html vendor-advisoryx_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2011/09/22/7 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2011/09/23/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2011/09/23/6 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2010-4818 Vendor Advisory
- https://bugs.freedesktop.org/show_bug.cgi?id=28823 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=740954 x_refsource_MISCIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-4818
- https://www.cve.org/CVERecord?id=CVE-2010-4818
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 5, 2012
Updated Aug 7, 2024
Reserved Aug 19, 2011
Link CVE-2010-4818
CISA Vulnrichment
Updated n/a