First published: Wed Dec 10 2014(Updated: )
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcDbeSwapBuffers or (2) SProcDbeSwapBuffers function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
X.Org xorg-server | <=1.16.2.99.901 | |
X.org X.org | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8097 is considered moderate severity due to its potential for denial of service and arbitrary code execution.
To fix CVE-2014-8097, upgrade your X.Org Server to version 1.16.3 or later.
CVE-2014-8097 affects X.Org Server versions before 1.16.3 and X11 version 6.1.
Yes, CVE-2014-8097 can be exploited by remote authenticated users.
Exploitation of CVE-2014-8097 can lead to denial of service or execution of arbitrary code.