Lucene search

K
ubuntuUbuntuUSN-514-1
HistorySep 18, 2007 - 12:00 a.m.

X.org vulnerability

2007-09-1800:00:00
ubuntu.com
33

4.3 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

Releases

  • Ubuntu 6.06

Packages

  • xorg-server -

Details

Aaron Plattner discovered that the Composite extension did not correctly
calculate the size of buffers when copying between different bit depths.
An authenticated user could exploit this to execute arbitrary code with
root privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.06noarchxserver-xorg-core< 1:1.0.2-0ubuntu10.7UNKNOWN
Ubuntu6.06noarchxdmx< 1:1.0.2-0ubuntu10.7UNKNOWN
Ubuntu6.06noarchxdmx-tools< 1:1.0.2-0ubuntu10.7UNKNOWN
Ubuntu6.06noarchxnest< 1:1.0.2-0ubuntu10.7UNKNOWN
Ubuntu6.06noarchxserver-xorg-dev< 1:1.0.2-0ubuntu10.7UNKNOWN
Ubuntu6.06noarchxvfb< 1:1.0.2-0ubuntu10.7UNKNOWN

4.3 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%