CVE-2008-1377
Last modified
CVE-2008-1377 is a vulnerability of currently unknown severity. The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.. EPSS estimates a 2.70% chance of exploitation in the next 30 days.
Description
The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X | X11 | r7.3 |
References
- http://secunia.com/advisories/30627Vendor Advisory
- http://secunia.com/advisories/30628Vendor Advisory
- http://secunia.com/advisories/30629Vendor Advisory
- http://secunia.com/advisories/30630Vendor Advisory
- http://secunia.com/advisories/30637Vendor Advisory
- http://secunia.com/advisories/30659Vendor Advisory
- http://secunia.com/advisories/30664Vendor Advisory
- http://secunia.com/advisories/30666Vendor Advisory
- http://secunia.com/advisories/30627Vendor Advisory
- http://secunia.com/advisories/30628Vendor Advisory
- http://secunia.com/advisories/30629Vendor Advisory
- http://secunia.com/advisories/30630Vendor Advisory
- http://secunia.com/advisories/30637Vendor Advisory
- http://secunia.com/advisories/30659Vendor Advisory
- http://secunia.com/advisories/30664Vendor Advisory
- http://secunia.com/advisories/30666Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1377?
How severe is CVE-2008-1377?
How do I fix CVE-2008-1377?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1371Absolute path traversal vulnerability in install/index.php i…
- CVE-2008-1372bzlib.c in bzip2 before 1.0.5 allows user-assisted remote at…
- CVE-2008-1373Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 a…
- CVE-2008-1374Integer overflow in pdftops filter in CUPS in Red Hat Enterp…
- CVE-2008-1375Race condition in the directory notification subsystem (dnot…
- CVE-2008-1376A certain Red Hat build script for nfs-utils before 1.0.9-35…
- CVE-2008-1378Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-1379Integer overflow in the fbShmPutImage function in the MIT-SH…
- CVE-2008-1380The JavaScript engine in Mozilla Firefox before 2.0.0.14, Th…
- CVE-2008-1381ZoneMinder before 1.23.3 allows remote authenticated users, …
- CVE-2008-1382libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0…
- CVE-2008-1383The docert function in ssl-cert.eclass, when used by src_com…
Are you affected by CVE-2008-1377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
