CVE-2014-8094

CVSS V2 Medium 6.5 CVSS V3 None
Description
Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
Overview
  • CVE ID
  • CVE-2014-8094
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2014-12-10T15:59:06
  • Last Modified Date
  • 2023-02-13T00:42:38
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:x.org:xorg-server:1.7.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.0.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.1.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.3.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.3.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.4.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.4.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.5.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.5.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.6.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.6.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.99.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.99.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.7.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.0.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.1.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.99.903:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.99.904:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.8.99.905:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.0.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.3.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.3.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.4.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.9.99.903:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.0.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.1.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.3.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.3.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.10.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.1.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.3.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.3.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.99.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.99.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.11.99.903:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.0.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.1.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.3.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.3.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.99.903:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.99.904:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.12.99.905:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.0.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.13.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.1.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.2:rc1:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.2.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.3.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.3.901:rc1:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.4.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.5.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.903:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.904:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.14.99.905:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.99.902:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.99.903:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.15.99.904:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.16.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.16.0.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.16.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.16.1.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.16.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.16.2.99.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:x.org:xorg-server:1.16.2.901:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:S/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • SINGLE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 6.5
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8
  • Impact Score
  • 6.4
History
Created Old Value New Value Data Type Notes
2022-05-10 09:53:17 Added to TrackCVE
2022-12-02 02:36:59 2014-12-10T15:59Z 2014-12-10T15:59:06 CVE Published Date updated
2022-12-02 02:36:59 2017-01-03T02:59:17 CVE Modified Date updated
2022-12-02 02:36:59 Modified Vulnerability Status updated
2023-02-02 21:04:46 2023-02-02T20:18:55 CVE Modified Date updated
2023-02-02 21:04:47 Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write. An integer overflow flaw was found in the way the X.Org server calculated memory requirements for certain DRI2 extension requests. A malicious, authenticated client could use this flaw to crash the X.Org server. Description updated
2023-02-02 21:04:52 References updated
2023-02-13 01:05:34 2023-02-13T00:42:38 CVE Modified Date updated
2023-02-13 01:05:34 An integer overflow flaw was found in the way the X.Org server calculated memory requirements for certain DRI2 extension requests. A malicious, authenticated client could use this flaw to crash the X.Org server. Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write. Description updated