XFree86 pixmap Integer Overflows May Let Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1014887
|
|
SecurityTracker URL: http://securitytracker.com/id?1014887
|
|
CVE Reference: CVE-2005-2495
(Links to External Site)
|
Updated: Nov 18 2005
|
Original Entry Date: Sep 13 2005
|
Impact: Execution of arbitrary code via local system, User access via local system
|
Version(s): 4.5.0
|
Description: A vulnerability was reported in XFree86. A local user may be able to gain elevated privileges.
The software does not properly parse pixmap images. A local user can create a specially crafted pixmap image that, when loaded by
the target user, will execute arbitrary code with elevate privileges.
The original bug report is available at:
https://bugs.freedesktop.org/show_bug.cgi?id=594
L
uke Hutchison reported this vulnerability.
|
Impact: A local user may be able to execute arbitrary code with elevated privileges.
|
Solution: No upstream fix was available at the time of this entry.
Red Hat has issued a fix for Red Hat Enterprise Linux 2.1:
https://rhn.redhat.com/errata/RHSA-2005-329.html
Red Hat has issued a fix for Red Hat Enterprise Linux 3:
https://rhn.redhat.com/errata/RHSA-2005-501.html
Gentoo has issued
a fix for Gentoo Linux:
http://security.gentoo.org/glsa/glsa-200509-07.xml
Red Hat has issued a fix for X11 on Red Hat Enterprise
Linux version 4, which is affected by this vulnerability:
https://rhn.redhat.com/errata/RHSA-2005-396.html
Sun has issued
T-Patchs for Sun Solaris:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101926-1
Sun has issued a fix for Sun Java
Desktop System (JDS):
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101953-1
|
Vendor URL: www.xfree86.org/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Mon, 12 Sep 2005 19:51:42 -0400
Subject: XFree86 pixmap vulnerability
|
CVE: CAN-2005-2495
https://bugs.freedesktop.org/show_bug.cgi?id=594
|
|