Wind River Support Network

HomeDefectsLIN5-19879
Fixed

LIN5-19879 : Security Advisory - xorg-server - CVE-2014-8100

Created: Dec 14, 2014    Updated: Dec 19, 2017
Resolved Date: Feb 28, 2015
Found In Version: 5.0.1.22
Fix Version: 5.0.1.25
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SProcRenderQueryVersion, (3) SProcRenderQueryPictFormats, (4) SProcRenderQueryPictIndexValues, (5) SProcRenderCreatePicture, (6) SProcRenderChangePicture, (7) SProcRenderSetPictureClipRectangles, (8) SProcRenderFreePicture, (9) SProcRenderComposite, (10) SProcRenderScale, (11) SProcRenderCreateGlyphSet, (12) SProcRenderReferenceGlyphSet, (13) SProcRenderFreeGlyphSet, (14) SProcRenderFreeGlyphs, or (15) SProcRenderCompositeGlyphs function.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8100

Other Downloads


Live chat
Online