Vulnerability CVE-2014-8094


Published: 2014-12-10

Description:
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
X.org -> Xorg-server 
X -> Xorg-server 
Oracle -> Solaris 
Debian -> Debian linux 

 References:
http://advisories.mageia.org/MGASA-2014-0532.html
http://secunia.com/advisories/61947
http://www.debian.org/security/2014/dsa-3095
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
http://www.securityfocus.com/bid/71601
http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/
https://security.gentoo.org/glsa/201504-06

Copyright 2024, cxsecurity.com

 

Back to Top