Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123226
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2014-1982)
Summary:The remote host is missing an update for the 'xorg-x11-server' package(s) announced via the ELSA-2014-1982 advisory.
Description:Summary:
The remote host is missing an update for the 'xorg-x11-server' package(s) announced via the ELSA-2014-1982 advisory.

Vulnerability Insight:
[1.1.1-48.107.0.1.el5_11]
- Added oracle-enterprise-detect.patch
- Replaced 'Red Hat' in spec file

[1.1.1-48.107]
- CVE-2014-8091 denial of service due to unchecked malloc in client
authentication (#1168680)
- CVE-2014-8092 integer overflow in X11 core protocol requests when
calculating memory needs for requests (#1168684)
- CVE-2014-8097 out of bounds access due to not validating length or offset
values in DBE extension (#1168705)
- CVE-2014-8095 out of bounds access due to not validating length or offset
values in XInput extension (#1168694)
- CVE-2014-8096 out of bounds access due to not validating length or offset
values in XC-MISC extension(#1168700)
- CVE-2014-8099 out of bounds access due to not validating length or offset
values in XVideo extension (#1168710)
- CVE-2014-8100 out of bounds access due to not validating length or offset
values in Render extension (#1168711)
- CVE-2014-8102 out of bounds access due to not validating length or offset
values in XFixes extension (#1168714)
- CVE-2014-8101 out of bounds access due to not validating length or offset
values in RandR extension (#1168713)
- CVE-2014-8093 xorg-x11-server: integer overflow in GLX extension requests
when calculating memory needs for requests (#1168688)
- CVE-2014-8098 xorg-x11-server: out of bounds access due to not validating
length or offset values in GLX extension (#1168707)

[1.1.1-48.104]
- xserver-1.1.1-randr-config-timestamps.patch: Backport timestamp comparison
fix from upstream RANDR code (#1006076)

[1.1.1-48.103]
- CVE-2013-6424: Fix OOB in trapezoid rasterization

Affected Software/OS:
'xorg-x11-server' package(s) on Oracle Linux 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-8091
61947
http://secunia.com/advisories/61947
62292
http://secunia.com/advisories/62292
71597
http://www.securityfocus.com/bid/71597
DSA-3095
http://www.debian.org/security/2014/dsa-3095
GLSA-201504-06
https://security.gentoo.org/glsa/201504-06
MDVSA-2015:119
http://www.mandriva.com/security/advisories?name=MDVSA-2015:119
http://advisories.mageia.org/MGASA-2014-0532.html
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/
Common Vulnerability Exposure (CVE) ID: CVE-2014-8092
71595
http://www.securityfocus.com/bid/71595
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-8093
71596
http://www.securityfocus.com/bid/71596
http://nvidia.custhelp.com/app/answers/detail/a_id/3610
Common Vulnerability Exposure (CVE) ID: CVE-2014-8095
71599
http://www.securityfocus.com/bid/71599
Common Vulnerability Exposure (CVE) ID: CVE-2014-8096
71598
http://www.securityfocus.com/bid/71598
Common Vulnerability Exposure (CVE) ID: CVE-2014-8097
71604
http://www.securityfocus.com/bid/71604
Common Vulnerability Exposure (CVE) ID: CVE-2014-8098
71606
http://www.securityfocus.com/bid/71606
Common Vulnerability Exposure (CVE) ID: CVE-2014-8099
71600
http://www.securityfocus.com/bid/71600
Common Vulnerability Exposure (CVE) ID: CVE-2014-8100
71602
http://www.securityfocus.com/bid/71602
Common Vulnerability Exposure (CVE) ID: CVE-2014-8101
71605
http://www.securityfocus.com/bid/71605
Common Vulnerability Exposure (CVE) ID: CVE-2014-8102
71608
http://www.securityfocus.com/bid/71608
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.