(Sun Issues Fix) X Memory Corruption Errors in Render and DBE Extensions Let Local Users Gain Root Privileges
|
|
SecurityTracker Alert ID: 1017663 |
|
SecurityTracker URL: http://securitytracker.com/id/1017663
|
|
CVE Reference:
CVE-2006-6101, CVE-2006-6102, CVE-2006-6103
(Links to External Site)
|
Date: Feb 16 2007
|
Impact:
Execution of arbitrary code via local system, Root access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 7.1-1.1.0, possibly other versions
|
Description:
Several vulnerabilities were reported in X. A local user can obtain root privileges on the target system.
A local user with the ability to send commands to an affected X server can trigger a memory corruption error in the ProcRenderAddGlyphs() function of the Render extension to execute arbitrary commands on the target system, typically with root privileges [CVE-2006-6101].
A memory corruption error also resides in the ProcDbeGetVisualInfo() function of the DBE extension [CVE-2006-6102].
A memory corruption error also resides in the ProcDbeSwapBuffers() function of the DBE extension [CVE-2006-6103].
The vendor was notified on December 4, 2006.
The XFree86 X server is also affected by these vulnerabilities.
Sean Larsson of iDefense Labs discovered these vulnerability.
|
Impact:
A local user can obtain root privileges on the target system.
|
Solution:
Sun has issued a fix for Solaris 8.
SPARC Platform
* Solaris 8 with patch 119067-06 or later and 109862-04 or later
x86 Platform
* Solaris 8 with patch 119068-06 or later and 109863-04 or later
A fix for Solaris 9 and 10 is pending.
The Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1
|
Vendor URL: sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1 (Links to External Site)
|
Cause:
Access control error, Input validation error
|
Underlying OS:
UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Tue, 13 Feb 2007 22:47:27 -0500
Subject: Multiple Integer Overflow Vulnerabilities in the X Font Server (xfs(1)) and the X Render and DBE Extensions
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1
CVE-2003-0730
CVE-2006-6101
CVE-2006-6102
CVE-2006-6103
|
|