bk99.de entertain the web since 1997

Security holes in the X.org X server

Summary

In January 2007 the X.org X server contained several integer overflow holes in the DBE module and the Render extension, affecting all versions since X.org 6.8.2. Faulty parameters could overwrite memory even outside the affected functions. This could only be exploited by an already authenticated client, and patches were available.

Ideas

  • Integer overflows lead to wrong memory sizes and thus to memory corruption.
  • The damage can hit distant parts of memory.
  • Authentication to the X server limited the circle of possible attackers.

Insights

  • An X server with root privileges turns every memory hole into a system risk.
  • Authentication lowers the risk but does not remove the cause.

Facts

  • Patches were available from freedesktop.org.

References

Critique

  • The report names no CVE identifiers, which makes matching with distribution updates harder.

Remarks

  • Modern distributions run the X server without root privileges or replace it with Wayland.

Recommendations

  • Use Wayland or a rootless X server where possible.
  • Do not allow X connections from the network; use SSH forwarding if needed.

Read the original article

Search the Web Archive