The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Vulnerability of libX11: buffer overflow of MakeBigReq

Synthesis of the vulnerability 

An attacker can generate a buffer overflow in applications using MakeBigReq() of libX11, in order to trigger a denial of service, and possibly to execute code.
Vulnerable products: Debian, VNX Operating Environment, VNX Series, Solaris, Ubuntu, libX11.
Severity of this weakness: 2/4.
Creation date: 08/04/2015.
Références of this bulletin: 56508, bulletinjul2015, CVE-2013-7439, DSA-2019-197, DSA-3224-1, USN-2568-1, VIGILANCE-VUL-16554.

Description of the vulnerability 

The libX11 library uses the MakeBigReq() macro to extend a query.

However, this macro performs a memmove() on 4 bytes past the buffer end. An overflow thus occurs.

An attacker can therefore generate a buffer overflow in applications using MakeBigReq() of libX11, in order to trigger a denial of service, and possibly to execute code.
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

This threat announce impacts software or systems such as Debian, VNX Operating Environment, VNX Series, Solaris, Ubuntu, libX11.

Our Vigil@nce team determined that the severity of this cybersecurity alert is medium.

The trust level is of type confirmed by the editor, with an origin of user shell.

An attacker with a expert ability can exploit this security alert.

Solutions for this threat 

libX11: version 1.6.0.
The version 1.6.0 is fixed:
  http://cgit.freedesktop.org/xorg/lib/libX11/

libX11: patch for MakeBigReq.
A patch is available in information sources.

Debian: new libx11 packages.
New packages are available:
  Debian 7: libx11 2:1.5.0-1+deb7u2

Dell EMC VNXe: version MR4 Service Pack 5.
The version MR4 Service Pack 5 is fixed:
  https://www.dell.com/support/

Solaris: patch for Third Party (07/2015).
A patch is available:
  https://support.oracle.com/rs?type=doc&id=1448883.1

Ubuntu: new libxrender1 packages.
New packages are available:
  Ubuntu 14.10: libxrender1 1:0.9.8-1build0.14.10.1
  Ubuntu 14.04 LTS: libxrender1 1:0.9.8-1build0.14.04.1
  Ubuntu 12.04 LTS: libx11-dev 2:1.4.99.1-0ubuntu2.3, libxrender1 1:0.9.6-2ubuntu0.2
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

Computer vulnerabilities tracking service 

Vigil@nce provides a computers vulnerabilities alert. Each administrator can customize the list of products for which he wants to receive vulnerability alerts.