CVE-2008-1377

Impact:
Important
Public Date:
2008-06-11
Bugzilla:
445403: CVE-2008-1377 X.org Record and Security extensions memory corruption

The MITRE CVE dictionary describes this issue as:

The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.

Find out more about CVE-2008-1377 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 4 (xorg-x11) RHSA-2008:0503 2008-06-11
Red Hat Enterprise Linux 5 (xorg-x11-server) RHSA-2008:0504 2008-06-11
Red Hat Enterprise Linux 2.1 (XFree86) RHSA-2008:0512 2008-06-11
Red Hat Enterprise Linux 3 (XFree86) RHSA-2008:0502 2008-06-11

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.