xorg-x11-server: out of bounds access due to not validating length or offset values in DRI3 & Present extensions
Published Dec 10, 2014
6.5
MEDIUMCVSS 2.0
EPSS 3.38%
Description
X.Org Server (aka xserver and xorg-server) 1.15.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) sproc_dri3_query_version, (2) sproc_dri3_open, (3) sproc_dri3_pixmap_from_buffer, (4) sproc_dri3_buffer_from_pixmap, (5) sproc_dri3_fence_from_fd, (6) sproc_dri3_fd_from_fence, (7) proc_present_query_capabilities, (8) sproc_present_query_version, (9) sproc_present_pixmap, (10) sproc_present_notify_msc, (11) sproc_present_select_input, or (12) sproc_present_query_capabilities function in the (a) DRI3 or (b) Present extension.
Affected products
No data.
- 1.15.0
- 1.15.0.901
- 1.15.1
- 1.15.2
- 1.15.99.901
- 1.15.99.902
- 1.15.99.903
- 1.15.99.904
- 1.16.0
- 1.16.0.901
- 1.16.1
- 1.16.1.901
- 1.16.2
- 1.16.2.99.901
- 1.16.2.901
No data.
Red Hat Enterprise Linux 6
xorg-x11-server-0:1.15.0-25.el6_6
Fixed · RHSA-2014:1983
Red Hat Enterprise Linux 7
xorg-x11-server-0:1.15.0-7.el7_0.3
Fixed · RHSA-2014:1983
Red Hat Enterprise Linux 5
xorg-x11-server
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | xorg-x11-server-0:1.15.0-25.el6_6 | Fixed | RHSA-2014:1983 |
| Red Hat Enterprise Linux 7 | xorg-x11-server-0:1.15.0-7.el7_0.3 | Fixed | RHSA-2014:1983 |
| Red Hat Enterprise Linux 5 | xorg-x11-server | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://secunia.com/advisories/61947 third-party-advisoryx_refsource_SECUNIA
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html x_refsource_CONFIRM
- http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/ x_refsource_CONFIRMPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2014-8103 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1168716 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-7950 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-8103
- https://security.gentoo.org/glsa/201504-06 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2014-8103
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/61947 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | x_refsource_CONFIRM | |
| http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/ | x_refsource_CONFIRMPatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2014-8103 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1168716 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-7950 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-8103 | ||
| https://security.gentoo.org/glsa/201504-06 | vendor-advisoryx_refsource_GENTOO | |
| https://www.cve.org/CVERecord?id=CVE-2014-8103 |
Change history (0)
No recorded changes yet.