CVE-2007-6427: Critical severity X.Org X Server vulnerability
Published Jan 18, 2008
·Updated
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
Affected Software
22 affected components
X.Org X Server<1.4.1
Canonical Ubuntu Linux=6.06
Canonical Ubuntu Linux=6.10
Canonical Ubuntu Linux=7.04
Canonical Ubuntu Linux=7.10
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Apple iOS and macOS<10.4.11
Apple iOS and macOS>=10.5.0<10.5.2
Fedoraproject Fedora=7
Fedoraproject Fedora=8
openSUSE openSUSE=10.2
openSUSE openSUSE=10.3
SUSE Linux=10.1
SUSE Linux Enterprise Desktop=9
SUSE Linux Enterprise Desktop=10
SUSE Linux Enterprise Desktop=10-sp1
SUSE Linux Enterprise Server=8
SUSE Linux Enterprise Server=9
SUSE Linux Enterprise Server=10-sp1
SUSE Linux Enterprise Software Development Kit=10-sp1
SUSE Open Enterprise Server
Remediation
Patch Available
Patch Available
Event History
Jan 18, 2008
CVE Published
11:00 PM
Jan 19, 2008
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6427?
CVE-2007-6427 has a high severity rating due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2007-6427?
To fix CVE-2007-6427, upgrade to X.Org Xserver version 1.4.1 or later.
3
What systems are affected by CVE-2007-6427?
CVE-2007-6427 affects various systems including older versions of X.org, Ubuntu, Debian, macOS, Fedora, and openSUSE.
4
Can CVE-2007-6427 be exploited remotely?
Yes, CVE-2007-6427 can be exploited by context-dependent attackers remotely if they can send specific requests.
5
Is CVE-2007-6427 related to any other vulnerabilities?
CVE-2007-6427 is different from CVE-2007-4990, although both involve vulnerabilities in the XInput extension.