Vulnerability Name: | CVE-2010-1166 (CCN-58301) | ||||||||||||||||||||||||||||
Assigned: | 2010-04-27 | ||||||||||||||||||||||||||||
Published: | 2010-04-27 | ||||||||||||||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||||||||||||||
Summary: | The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.6 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: secalert@redhat.com Type: Exploit, Patch secalert@redhat.com Source: MITRE Type: CNA CVE-2010-1166 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: RHSA-2010-0382 Important: xorg-x11-server security update Source: CCN Type: SA41049 Sun Solaris Xorg Server Render Extension Memory Corruption Vulnerability Source: CCN Type: SECTRACK ID: 1023929 X.org Xserver mod() Calculation Error Lets Remote Users Execute Arbitrary Code Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: OSVDB ID: 64246 X.Org X Window System (X11) Render Extension fbpict.c fbComposite Function Macro Definition Remote DoS Source: CCN Type: BID-39758 X.Org X Server RENDER Extension 'mod()' Remote Memory Corruption Vulnerability Source: CCN Type: USN-939-1 X.org vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: X.Org Foundation Web site X.Org Wiki - Home Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: Red Hat Bugzilla Bug 582601 CVE-2010-1166 Xorg: X server Render extension memory corruption Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN xorg-render-fbcomposite-code-execution(58301) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |