Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
X.Org X server Record/Security扩展堆溢出漏洞
Vulnerability Description
Xorg X Server是多个厂商操作系统中所捆绑的X窗口系统显示服务器。 X.Org X server的Record和Security扩展从客户端请求中获得了不可信任的值并用于交换客户端请求后的堆内存字节序列。由于没有验证所要交换的字节数,恶意请求可能破坏堆内存。以下函数中包含有有漏洞的代码: SProcSecurityGenerateAuthorization() SProcRecordCreateContext() SProcRecordRegisterClients() 如果攻击者能够访问控制台
CVSS Information
N/A
Vulnerability Type
N/A