CVE-2004-0093: High severity Xfree86 Project X11r6 vulnerability
Published Mar 15, 2004
·Updated
XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).
Affected Software
7 affected components
Xfree86 Project X11r6=4.1.0
Xfree86 Project X11r6=4.3.0
Xfree86 Project X11r6=4.2.1
Xfree86 Project X11r6=4.2.0
Xfree86 Project X11r6=4.1.12
Xfree86 Project X11r6=4.2.1
Xfree86 Project X11r6=4.1.11
Remediation
Patch Available
Event History
Mar 15, 2004
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0093?
CVE-2004-0093 has a critical severity rating due to the potential for remote denial of service and arbitrary code execution.
2
How do I fix CVE-2004-0093?
To fix CVE-2004-0093, update to a patched version of XFree86 that resolves the out-of-bounds array index issue.
3
Which versions of XFree86 are affected by CVE-2004-0093?
CVE-2004-0093 affects XFree86 versions 4.1.0, 4.1.11, 4.1.12, 4.2.0, 4.2.1, and 4.3.0.
4
Can CVE-2004-0093 lead to remote code execution?
Yes, CVE-2004-0093 can potentially allow remote attackers to execute arbitrary code due to an out-of-bounds access.
5
Is there a workaround for CVE-2004-0093?
There are no known workarounds for CVE-2004-0093; updating the software is the recommended action.