CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:S/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
86.4%
USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was
found on Ubuntu 10.04 LTS that affected GLX support.
This update temporarily disables the fix for CVE-2010-4818 that introduced
the regression.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly execute arbitrary code
with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2010-4818)
It was discovered that the X server incorrectly handled certain malformed
input. An authorized attacker could exploit this to cause the X server to
crash, leading to a denial or service, or possibly read arbitrary data from
the X server process. This issue only affected Ubuntu 10.04 LTS.
(CVE-2010-4819)
Vladz discovered that the X server incorrectly handled lock files. A local
attacker could use this flaw to determine if a file existed or not.
(CVE-2011-4028)
Vladz discovered that the X server incorrectly handled setting lock file
permissions. A local attacker could use this flaw to gain read permissions
on arbitrary files and view sensitive information. (CVE-2011-4029)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 10.04 | noarch | xserver-xorg-core | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xdmx | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xdmx-tools | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xnest | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xserver-xephyr | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xserver-xfbdev | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xserver-xorg-core-dbg | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xserver-xorg-dev | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |
Ubuntu | 10.04 | noarch | xvfb | < 2:1.7.6-2ubuntu7.9 | UNKNOWN |