CVE Vulnerabilities

CVE-2015-3418

Divide By Zero

Published: Dec 13, 2016 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.3 LOW
AV:A/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Xorg-server X.org * 1.16.3 (including)
Red Hat Enterprise Linux 6 RedHat xorg-x11-server-0:1.15.0-36.el6 *
Xorg-server Ubuntu devel *
Xorg-server Ubuntu lucid *
Xorg-server Ubuntu precise *
Xorg-server Ubuntu trusty *
Xorg-server Ubuntu upstream *
Xorg-server Ubuntu utopic *
Xorg-server Ubuntu vivid *
Xorg-server-lts-quantal Ubuntu precise *
Xorg-server-lts-raring Ubuntu precise *
Xorg-server-lts-saucy Ubuntu precise *
Xorg-server-lts-trusty Ubuntu precise *

References