First published: Tue Dec 13 2016(Updated: )
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu X Server Legacy | <=1.16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3418 has a severity rating that indicates a denial of service vulnerability in X.Org Server.
To fix CVE-2015-3418, you should upgrade X.Org Server to version 1.16.4 or later.
CVE-2015-3418 affects X.Org Server versions up to and including 1.16.3.
CVE-2015-3418 is a denial of service vulnerability caused by a divide-by-zero error.
Yes, CVE-2015-3418 can be exploited remotely if an attacker sends a specially crafted zero-height PutImage request.