PT-2006-1047 · X.Org+1 · X.Org Server+1

Bart Massey

·

Published

2006-05-02

·

Updated

2018-10-18

·

CVE-2006-1526

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: X.org X server versions 6.8.0 up to 6.8.2-r6
Description: The issue is related to a buffer overflow in the X render (Xrender) extension, which can cause a denial of service (crash). This can be triggered by specific requests, such as XRenderCompositeTriStrip and XRenderCompositeTriFan, due to an incorrect memory allocation caused by a typo in an expression. The typo involves using a "&" operator instead of a "*" operator.
Recommendations: For X.org X server versions 6.8.0 up to 6.8.2-r6, update to version 6.8.2-r7 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09502
CVE-2006-1526
RHSA-2006:0451
RHSA-2006_0451

Affected Products

Red Hat
X.Org Server