CVE-2014-8098: Buffer Overflow
The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) glXDispRender, (2) glXDispRenderLarge, (3) glXDispSwapVendorPrivate, (4) glXDispSwapVendorPrivateWithReply, (5) setclientinfo, (6) glXDispSwapSetClientInfoARB, (7) DoSwapInterval, (8) DoGetProgramString, (9) DoGetString, (10) glXDispSwapRenderMode, (11) glXDispGetCompressedTexImage, (12) glXDispSwapGetCompressedTexImage, (13) glXDispFeedbackBuffer, (14) glXDispSwapFeedbackBuffer, (15) glXDispSelectBuffer, (16) glXDispSwapSelectBuffer, (17) glXDispFlush, (18) glXDispSwapFlush, (19) glXDispFinish, (20) glXDispSwapFinish, (21) glXDispReadPixels, (22) glXDispSwapReadPixels, (23) glXDispGetTexImage, (24) glXDispSwapGetTexImage, (25) glXDispGetPolygonStipple, (26) glXDispSwapGetPolygonStipple, (27) glXDispGetSeparableFilter, (28) glXDispGetSeparableFilterEXT, (29) glXDispGetConvolutionFilter, (30) glXDispGetConvolutionFilterEXT, (31) glXDispGetHistogram, (32) glXDispGetHistogramEXT, (33) glXDispGetMinmax, (34) glXDispGetMinmaxEXT, (35) glXDispGetColorTable, (36) glXDispGetColorTableSGI, (37) GetSeparableFilter, (38) GetConvolutionFilter, (39) GetHistogram, (40) GetMinmax, or (41) GetColorTable function.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8098?
CVE-2014-8098 has a severity rating indicating a potential risk for denial of service or remote code execution.
How do I fix CVE-2014-8098?
To fix CVE-2014-8098, update X.Org Server or any affected XFree86 installations to versions that are patched against this vulnerability.
Which systems are affected by CVE-2014-8098?
CVE-2014-8098 affects Debian 7.0, XFree86 version 4.0, and X.Org X11 version 6.7 along with X.Org Server versions up to 1.16.2.99.901.
Can CVE-2014-8098 be exploited remotely?
Yes, CVE-2014-8098 can be exploited by remote authenticated users to cause denial of service or potentially execute arbitrary code.
What types of issues does CVE-2014-8098 cause?
CVE-2014-8098 can lead to out-of-bounds reads or writes, resulting in denial of service or the execution of arbitrary code.