Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.
Name | Vendor | Start Version | End Version |
---|---|---|---|
X.org_x11 | X | 6.0 (including) | 6.0 (including) |
X.org_x11 | X | 6.1 (including) | 6.1 (including) |
X.org_x11 | X | 6.3 (including) | 6.3 (including) |
X.org_x11 | X | 6.4 (including) | 6.4 (including) |
X.org_x11 | X | 6.5.1 (including) | 6.5.1 (including) |
X.org_x11 | X | 6.6 (including) | 6.6 (including) |
X.org_x11 | X | 6.7 (including) | 6.7 (including) |
X.org_x11 | X | 6.8 (including) | 6.8 (including) |
X.org_x11 | X | 6.8.1 (including) | 6.8.1 (including) |
X.org_x11 | X | 6.8.2 (including) | 6.8.2 (including) |
X.org_x11 | X | 6.9.0 (including) | 6.9.0 (including) |
X.org_x11 | X | 7.0 (including) | 7.0 (including) |
X.org_x11 | X | 7.1 (including) | 7.1 (including) |
X.org_x11 | X | 7.2 (including) | 7.2 (including) |
X.org_x11 | X | 7.3 (including) | 7.3 (including) |
X.org_x11 | X | 7.4 (including) | 7.4 (including) |
X.org_x11 | X | 7.5 (including) | 7.5 (including) |
X.org_x11 | X | 7.5-rc1 (including) | 7.5-rc1 (including) |
X.org_x11 | X | 7.6 (including) | 7.6 (including) |
X.org_x11 | X | 7.6-rc1 (including) | 7.6-rc1 (including) |
X.org_x11 | X | 7.7 (including) | 7.7 (including) |
X.org_x11 | X | 7.7-rc1 (including) | 7.7-rc1 (including) |
Red Hat Enterprise Linux 5 | RedHat | xorg-x11-server-0:1.1.1-48.101.el5_10.1 | * |
Red Hat Enterprise Linux 6 | RedHat | xorg-x11-server-0:1.13.0-11.1.el6_4.2 | * |
Xorg-server | Ubuntu | devel | * |
Xorg-server | Ubuntu | lucid | * |
Xorg-server | Ubuntu | precise | * |
Xorg-server | Ubuntu | quantal | * |
Xorg-server | Ubuntu | raring | * |
Xorg-server | Ubuntu | upstream | * |
Xorg-server-lts-quantal | Ubuntu | precise | * |
Xorg-server-lts-raring | Ubuntu | precise | * |