[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#349251: CVE-2006-0197: XClientMessageEvent struct issue on 64 bit



Package: xorg-x11
Severity: normal
Version: 6.9.0.dfsg.1-4
Tags: security

CVE-2006-0197 describes a potential security problem as follows:

  The XClientMessageEvent struct used in certain components of X.Org 6.8.2
  and earlier, possibly including (1) the X server and (2) Xlib, uses a
  "long" specifier for elements of the l array, which results in
  inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and
  might allow attackers to cause a denial of service (application crash)
  and possibly conduct other attacks.

With details here:

http://www.securityfocus.com/archive/1/archive/1/421256/100/0/threaded

The struct remains the same in version 6.9.0.dfsg.1-4. I don't know if
this is actually exploitable or even a bug at all, so please
investigate.

-- 
see shy jo

Attachment: signature.asc
Description: Digital signature


Reply to: