search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Multiple X servers fail to properly allocate memory for large pixmaps

Vulnerability Note VU#102441

Original Release Date: 2005-09-13 | Last Revised: 2005-11-03

Overview

Multiple X Window System servers contain a pixmap memory allocation flaw that may allow local users to execute code with elevated privileges.

Description

Multiple X Window System server applications share code that may contain a flaw in the memory allocation for large pixmaps. The affected products include the X.Org and XFree86 X server applications, possibly among others.

An integer overflow condition may result in a memory allocation request returning an allocated region that is incorrectly sized. The client may then be able to use the XDrawPoint() and XGetImage() functions to read and write to arbitrary locations in the X server's address space.

Impact

A malicious local authenticated attacker may be able to execute arbitrary code with the privileges of the X server.

Solution

Apply an update
Contact your vendor for updates, fixes, and workarounds.

Vendor Information

102441
 

View all 42 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Luke Hutchison and Søren Sandmann Pedersen for reporting this vulnerability.

This document was written by Ken MacInnis.

Other Information

CVE IDs: CVE-2005-2495
Severity Metric: 7.43
Date Public: 2005-09-12
Date First Published: 2005-09-13
Date Last Updated: 2005-11-03 14:41 UTC
Document Revision: 38

Sponsored by CISA.