PT-2006-1047 · X.Org+1 · X.Org Server+1
Bart Massey
·
Published
2006-05-02
·
Updated
2018-10-18
·
CVE-2006-1526
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
X.org X server versions 6.8.0 up to 6.8.2-r6
Description:
The issue is related to a buffer overflow in the X render (Xrender) extension, which can cause a denial of service (crash). This can be triggered by specific requests, such as
XRenderCompositeTriStrip and XRenderCompositeTriFan, due to an incorrect memory allocation caused by a typo in an expression. The typo involves using a "&" operator instead of a "*" operator.Recommendations:
For X.org X server versions 6.8.0 up to 6.8.2-r6, update to version 6.8.2-r7 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
X.Org Server