cbcvebase.
CVE-2010-4819
published 2012-09-05

CVE-2010-4819: The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and…

low3.6CVSS 3.1
AVLACLAuNCPINAP
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."

Affected

9 ranges
VendorProductVersion rangeFixed in
debianxorg-server< xorg-server 2:1.9.0.901-1 (bookworm)xorg-server 2:1.9.0.901-1 (bookworm)
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
x.orgxorg-server>= 0 < 2:1.9.0.901-12:1.9.0.901-1
xx.org-xserver<= 1.7.7
xx.org-xserver
xx.org-xserver
xx.org-xserver

CVSS provenance

nvd3.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv3.6LOW