The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
The product divides a value by zero.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xorg-server | X.org | * | 1.16.3 (including) |
Red Hat Enterprise Linux 6 | RedHat | xorg-x11-server-0:1.15.0-36.el6 | * |
Xorg-server | Ubuntu | devel | * |
Xorg-server | Ubuntu | lucid | * |
Xorg-server | Ubuntu | precise | * |
Xorg-server | Ubuntu | trusty | * |
Xorg-server | Ubuntu | upstream | * |
Xorg-server | Ubuntu | utopic | * |
Xorg-server | Ubuntu | vivid | * |
Xorg-server-lts-quantal | Ubuntu | precise | * |
Xorg-server-lts-raring | Ubuntu | precise | * |
Xorg-server-lts-saucy | Ubuntu | precise | * |
Xorg-server-lts-trusty | Ubuntu | precise | * |