CVE-2007-6427
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.28% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- x.org/x server · canonical/ubuntu linux · debian/debian linux · apple/mac os x · fedoraproject/fedora · opensuse/opensuse · suse/linux · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · suse/open enterprise server
- Source
- cve@mitre.org
References
- http://bugs.gentoo.org/show_bug.cgi?id=204362Issue Tracking, Patch, Third Party Advisory
- http://docs.info.apple.com/article.html?artnum=307562Broken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321Broken Link
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=643Broken Link
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlMailing List
- http://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/28273Third Party Advisory
- http://secunia.com/advisories/28532Third Party Advisory
- http://secunia.com/advisories/28535Third Party Advisory
- http://secunia.com/advisories/28536Third Party Advisory
- http://secunia.com/advisories/28539Third Party Advisory
- http://secunia.com/advisories/28540Third Party Advisory
- http://secunia.com/advisories/28542Third Party Advisory
- http://secunia.com/advisories/28543Third Party Advisory
- http://secunia.com/advisories/28550Third Party Advisory
- http://secunia.com/advisories/28584Third Party Advisory
- http://secunia.com/advisories/28592Third Party Advisory
- http://secunia.com/advisories/28616Third Party Advisory
- http://secunia.com/advisories/28693Third Party Advisory
- http://secunia.com/advisories/28718Third Party Advisory
- http://secunia.com/advisories/28838Third Party Advisory
- http://secunia.com/advisories/28843Third Party Advisory
- http://secunia.com/advisories/28885Third Party Advisory
- http://secunia.com/advisories/28941Third Party Advisory
- http://secunia.com/advisories/29139Third Party Advisory
- http://secunia.com/advisories/29420Third Party Advisory
- http://secunia.com/advisories/29622Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.