CVE-2007-6429

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
18/01/2008
Last modified:
09/04/2025

Description

Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:x.org:evi:*:*:*:*:*:*:*:*
cpe:2.3:a:x.org:mit-shm:*:*:*:*:*:*:*:*
cpe:2.3:a:x.org:xserver:*:*:*:*:*:*:*:* 1.4 (including)


References to Advisories, Solutions, and Tools