CVE Vulnerabilities

CVE-2015-3418

Divide By Zero

Published: Dec 13, 2016 | Modified: Aug 29, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.3 LOW
AV:A/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.

Weakness

The product divides a value by zero.

Affected Software

NameVendorStart VersionEnd Version
X_serverX.org*1.16.3 (including)
Red Hat Enterprise Linux 6RedHatxorg-x11-server-0:1.15.0-36.el6*
Xorg-serverUbuntudevel*
Xorg-serverUbuntuesm-infra-legacy/trusty*
Xorg-serverUbuntulucid*
Xorg-serverUbuntuprecise*
Xorg-serverUbuntutrusty*
Xorg-serverUbuntutrusty/esm*
Xorg-serverUbuntuupstream*
Xorg-serverUbuntuutopic*
Xorg-serverUbuntuvivid*
Xorg-server-lts-quantalUbuntuprecise*
Xorg-server-lts-raringUbuntuprecise*
Xorg-server-lts-saucyUbuntuprecise*
Xorg-server-lts-trustyUbuntuprecise*

References