CVE-2015-3418: Divide by Zero
Published Dec 13, 2016
·Updated
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
Affected Software
2 affected components
X.Org xorg-server<=1.16.3
X.Org X Server<=1.16.3
Remediation
Event History
Dec 13, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-3418?
CVE-2015-3418 has a severity rating that indicates a denial of service vulnerability in X.Org Server.
2
How do I fix CVE-2015-3418?
To fix CVE-2015-3418, you should upgrade X.Org Server to version 1.16.4 or later.
3
What systems are affected by CVE-2015-3418?
CVE-2015-3418 affects X.Org Server versions up to and including 1.16.3.
4
What type of vulnerability is CVE-2015-3418?
CVE-2015-3418 is a denial of service vulnerability caused by a divide-by-zero error.
5
Can CVE-2015-3418 be exploited remotely?
Yes, CVE-2015-3418 can be exploited remotely if an attacker sends a specially crafted zero-height PutImage request.