Submitted by KeesCook on Thu, 2006-05-04 12:05
Referenced CVEs:
CVE-2006-1526
Description:
===========================================================
Ubuntu Security Notice USN-280-1 May 04, 2006
xorg vulnerability
CVE-2006-1526
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)
The following packages are affected:
xserver-xorg
xserver-xorg-core
The problem can be corrected by upgrading the affected package to
version 6.8.2-10.2 (for Ubuntu 5.04) or 6.8.2-77.1 (for Ubuntu 5.10).
After a standard system upgrade you need to restart X.org by
restarting your session to effect the necessary changes.
Details follow:
The Render extension of the X.org server incorrectly calculated the
size of a memory buffer, which led to a buffer overflow. A local
attacker could exploit this to crash the X server or even execute
arbitrary code with root privileges.


