René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

254 lines
7.6 KiB
JSON

{
"id": "CVE-2007-6428",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-01-18T23:00:00.000",
"lastModified": "2018-10-15T21:53:31.817",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index."
},
{
"lang": "es",
"value": "La funci\u00f3n ProcGetReservedColormapEntries de la extensi\u00f3n TOG-CUP de X.Org Xserver versiones anteriores a 1.4.1 permite a atacantes locales o remotos dependientes del contexto leer el contenido de ubicaciones de memoria de su elecci\u00f3n mediante peticiones conteniendo un valor de 32 bits que se utiliza inapropiadamente como un \u00edndice de array."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:x.org:tog-cup:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CCB67CA9-98C0-4111-AF1E-1357D2DE2116"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:x.org:xserver:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.4",
"matchCriteriaId": "EBC8352E-BBB6-4B41-AD07-447D8D71CE7D"
}
]
}
]
}
],
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=204362",
"source": "cve@mitre.org"
},
{
"url": "http://docs.info.apple.com/article.html?artnum=307562",
"source": "cve@mitre.org"
},
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=644",
"source": "cve@mitre.org"
},
{
"url": "http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.freedesktop.org/archives/xorg/2008-January/031918.html",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200801-09.xml",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200804-05.xml",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1019232",
"source": "cve@mitre.org"
},
{
"url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-103200-1",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-200153-1",
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-039.htm",
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-078.htm",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2008/dsa-1466",
"source": "cve@mitre.org"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:021",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:022",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:023",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:025",
"source": "cve@mitre.org"
},
{
"url": "http://www.openbsd.org/errata41.html#012_xorg",
"source": "cve@mitre.org"
},
{
"url": "http://www.openbsd.org/errata42.html#006_xorg",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0029.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0030.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0031.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/487335/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27336",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/bid/27355",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0179",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0184",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0497/references",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0703",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0924/references",
"source": "cve@mitre.org"
},
{
"url": "http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile112539&label=AIX%20X%20server%20multiple%20vulnerabilities",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39761",
"source": "cve@mitre.org"
},
{
"url": "https://issues.rpath.com/browse/RPL-2010",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11754",
"source": "cve@mitre.org"
},
{
"url": "https://usn.ubuntu.com/571-1/",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.html",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.html",
"source": "cve@mitre.org"
}
]
}