CVE-2007-6428

The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.

Date published : 2008-01-18

http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html

http://www.securityfocus.com/bid/27336