xorg-server: denial of service
| Package(s): | xorg-server | CVE #(s): | CVE-2015-3418 | ||||||||||||
| Created: | May 4, 2015 | Updated: | May 6, 2015 | ||||||||||||
| Description: | From the Debian LTS advisory:
This issue (CVE-2015-3418) is a regression which got introduced by fixing CVE-2014-8092. The above referenced version of xorg-server in Debian squeeze-lts fixes this regression in the following way: The length checking code validates PutImage height and byte width by making sure that byte-width >= INT32_MAX / height. If height is zero, this generates a divide by zero exception. Allow zero height requests explicitly, bypassing the INT32_MAX check (in dix/dispatch.c). | ||||||||||||||
| Alerts: |
| ||||||||||||||
