CVE-2007-6429

Publication date 18 January 2008

Last updated 24 July 2024


Ubuntu priority

Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.

Status

Package Ubuntu Release Status
xorg-server 7.10 gutsy
Fixed 2:1.3.0.0.dfsg-12ubuntu8.1
7.04 feisty
Fixed 2:1.2.0-3ubuntu8.1
6.10 edgy
Fixed 1:1.1.1-0ubuntu12.3
6.06 LTS dapper
Fixed 1:1.0.2-0ubuntu10.8