Oval Definition:oval:com.ubuntu.precise:def:20148093000
Revision Date:2014-12-10Version:1
Title:CVE-2014-8093 on Ubuntu 12.04 LTS (precise) - medium.
Description:Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3) __glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5) GetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8) GetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11) __GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize, (14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17) __glXImageSize, or (18) __glXSeparableFilter2DReqSize function, which triggers an out-of-bounds read or write.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-8093
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • The 'xorg-server' package in precise was vulnerable but has been fixed (note: '2:1.11.4-0ubuntu10.15').
  • OR The 'xorg-server-lts-trusty' package in precise was vulnerable but has been fixed (note: '2:1.15.1-0ubuntu2~precise3').
  • BACK