5.5
CVSSv2

CVE-2007-2437

Published: 02/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 5.5 | Impact Score: 6.9 | Exploitability Score: 5.1
VMScore: 555
Vector: AV:A/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and previous versions, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.

Vulnerable Product Search on Vulmon Subscribe to Product

x.org x window system 7.1

x.org x window system 7.2

x.org x window system 7.0

x.org xserver

Vendor Advisories

Debian Bug report logs - #422936 CVE-2007-2437: Xrender extension allows remote DoS Package: xorg-server; Maintainer for xorg-server is Debian X Strike Force <debian-x@listsdebianorg>; Reported by: Micah Anderson <micah@debianorg> Date: Tue, 8 May 2007 22:39:01 UTC Severity: important Tags: patch Fixed in versio ...

Exploits

source: wwwsecurityfocuscom/bid/23741/info XOrg X Window System Xserver is prone to a denial-of-service vulnerabilty because the software fails to properly handle exceptional conditions Attackers who can connect to a vulnerable X server may exploit this issue to crash the targeted server, denying futher service to legitimate users X ...