CVE-1999-0778: Buffer Overflow
Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Xi Graphics Accelerated-X serverfrom your environment.Uninstall or disable the Xi Graphics Accelerated-X server until a vendor-supplied fix is available to eliminate the vulnerable component from the system.
- Compensating control
Prevent untrusted local users from accessing or invoking the Accelerated-X server. Apply OS-level access controls (file permissions, local account restrictions, sudo rules, MAC/SELinux policies, or local firewall rules) to restrict who can start or interact with the display/query interfaces so local users cannot exploit long display or query parameters to gain root.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0778?
CVE-1999-0778 is considered to be a critical vulnerability that allows local users to gain root access.
How do I fix CVE-1999-0778?
To fix CVE-1999-0778, upgrade to a version of the Xi Graphics Accelerated-X server that is not vulnerable, specifically versions later than 5.x.
What versions of Xi Graphics Accelerated-X server are affected by CVE-1999-0778?
CVE-1999-0778 affects versions 4 and 5 of the Xi Graphics Accelerated-X server.
Who is affected by CVE-1999-0778?
Local users with access to the system are affected as they can exploit CVE-1999-0778 to gain elevated privileges.
What type of vulnerability is CVE-1999-0778?
CVE-1999-0778 is a buffer overflow vulnerability.