(HP Issues Fix for HP-UX) X Memory Corruption Errors in Render and DBE Extensions Let Local Users Gain Root Privileges
|
|
SecurityTracker Alert ID: 1018279 |
|
SecurityTracker URL: http://securitytracker.com/id/1018279
|
|
CVE Reference:
CVE-2006-6101, CVE-2006-6102, CVE-2006-6103
(Links to External Site)
|
Date: Jun 22 2007
|
Impact:
Execution of arbitrary code via local system, Root access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 7.1-1.1.0, possibly other versions
|
Description:
Several vulnerabilities were reported in X. A local user can obtain root privileges on the target system.
A local user with the ability to send commands to an affected X server can trigger a memory corruption error in the ProcRenderAddGlyphs() function of the Render extension to execute arbitrary commands on the target system, typically with root privileges [CVE-2006-6101].
A memory corruption error also resides in the ProcDbeGetVisualInfo() function of the DBE extension [CVE-2006-6102].
A memory corruption error also resides in the ProcDbeSwapBuffers() function of the DBE extension [CVE-2006-6103].
The vendor was notified on December 4, 2006.
The XFree86 X server is also affected by these vulnerabilities.
Sean Larsson of iDefense Labs discovered these vulnerability.
|
Impact:
A local user can obtain root privileges on the target system.
|
Solution:
HP has issued the following patches, available at:
http://itrc.hp.com
HP-UX B.11.11:
PHSS_34389 or subsequent
HP-UX B.11.23:
PHSS_36452 or subsequent
HP-UX B.11.31:
PHSS_36123 or subsequent
The HP advisory is available at:
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01075678-1
|
Cause:
Access control error, Input validation error
|
Underlying OS:
UNIX (HP/UX)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 22 Jun 2007 00:15:43 -0400
Subject: HPSBUX02225 SSRT071295 rev.1 - HP-UX Running Xserver, Local Denial of Service (DoS)
|
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01075678-1
CVE-2006-6101, CVE-2006-6102, CVE-2006-6103
|
|