CVE-2007-6429
EPSS 2.3%
Description
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.
How to fix CVE-2007-6429
To remediate CVE-2007-6429, upgrade the affected package to a fixed version below.
- Debian/xorg-server—upgrade to 2:1.4.1~git20080105-2 or later
Is CVE-2007-6429 being exploited?
Low — EPSS is 2.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:1.4.1~git20080105-2