CVE-2014-8091: Null Pointer Dereference
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a crafted connection request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8091?
CVE-2014-8091 is classified as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-8091?
To mitigate CVE-2014-8091, upgrade the X.Org Server to version 1.16.3 or later.
What applications are affected by CVE-2014-8091?
CVE-2014-8091 affects X.Org Server versions prior to 1.16.3 and X11 version 5.0.
What type of vulnerability is CVE-2014-8091?
CVE-2014-8091 is a memory management vulnerability that can lead to a denial of service due to insufficient checks on malloc return values.
Can CVE-2014-8091 be exploited remotely?
Yes, CVE-2014-8091 can be exploited remotely, allowing attackers to cause service disruptions.