(Sun Issues FIx) X Integer Overflow in ProcRenderCreateCursor() Lets Local Users and Remote Authenticated Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1020286 |
|
SecurityTracker URL: http://securitytracker.com/id/1020286
|
|
CVE Reference:
CVE-2008-2361
(Links to External Site)
|
Updated: Apr 10 2009
|
Original Entry Date: Jun 13 2008
|
Impact:
Execution of arbitrary code via network, Root access via local system, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): X11R7.3
|
Description:
A vulnerability was reported in the X Window System. A remote authenticated user can execute arbitrary code on the target system. A local user can obtain elevated privileges on the target system.
A remote authenticated user can send specially crafted data to trigger an integer overflow in the ProcRenderCreateCursor() function and execute arbitrary code on the target X server. The code will run with the privileges of the target server (which may be root privileges on many systems).
A local user can execute arbitrary commands on the target system with elevated privileges.
The RENDER Extension is affected.
The vendor was notified on March 26, 2008.
regenrecht reported this vulnerability via iDefense.
|
Impact:
A remote authenticated user can execute arbitrary code on the target system.
A local user can obtain elevated privileges on the target system.
|
Solution:
Sun has issued the following fixes.
SPARC Platform
* Solaris 8 with patch 119067-10 or later (for Xsun(1))
* Solaris 9 with patch 112785-64 or later (for Xsun(1))
* Solaris 10 with patches 119059-44 or later and 125719-12 or later
* OpenSolaris based upon builds snv_92 or later
x86 Platform
* Solaris 8 with patch 119068-10 or later (for Xsun(1))
* Solaris 9 with patch 112786-53 or later (for Xsun(1))
* Solaris 9 with patch 118908-06 or later (for Xorg)
* Solaris 10 with patches 119060-43 or later and 125720-23 or later
* OpenSolaris based upon builds snv_92 or later
The Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238686-1
|
Vendor URL: x.org/ (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 13 Jun 2008 17:47:02 -0400
Subject: http://sunsolve.sun.com/search/document.do?assetkey=1-66-238686-1
|
CVE-2008-1377
CVE-2008-1379
CVE-2008-2360
CVE-2008-2361
CVE-2008-2362
|
|