Lucene search

K
ubuntuUbuntuUSN-448-1
HistoryApr 03, 2007 - 12:00 a.m.

X.org vulnerabilities

2007-04-0300:00:00
ubuntu.com
31

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.05 Low

EPSS

Percentile

92.9%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06
  • Ubuntu 5.10

Details

Sean Larsson of iDefense Labs discovered that the MISC-XC extension of
Xorg did not correctly verify the size of allocated memory. An
authenticated user could send a specially crafted X11 request and
execute arbitrary code with root privileges. (CVE-2007-1003)

Greg MacManus of iDefense Labs discovered that the BDF font handling
code in Xorg and FreeType did not correctly verify the size of allocated
memory. If a user were tricked into using a specially crafted font, a
remote attacker could execute arbitrary code with root privileges.
(CVE-2007-1351, CVE-2007-1352)

OSVersionArchitecturePackageVersionFilename
Ubuntu6.10noarchlibxfont1< 1:1.2.0-0ubuntu3.1UNKNOWN
Ubuntu6.10noarchxserver-xorg-core< 1:1.1.1-0ubuntu12.2UNKNOWN
Ubuntu6.10noarchlibfreetype6< 2.2.1-5ubuntu0.1UNKNOWN
Ubuntu6.06noarchlibxfont1< 1:1.0.0-0ubuntu3.3UNKNOWN
Ubuntu6.06noarchxserver-xorg-core< 1:1.0.2-0ubuntu10.6UNKNOWN
Ubuntu6.06noarchlibfreetype6< 2.1.10-1ubuntu2.3UNKNOWN
Ubuntu5.10noarchlibxfont1< 1:0.99.0+cvs.20050909-1.3UNKNOWN
Ubuntu5.10noarchxserver-xorg-core< 6.8.2-77.3UNKNOWN
Ubuntu5.10noarchlibfreetype6< 2.1.7-2.4ubuntu1.3UNKNOWN

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.05 Low

EPSS

Percentile

92.9%