CVE-2015-3418
published 2016-12-13CVE-2015-3418: The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service…
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.31%
81.6th percentile
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.16.4-1 (bookworm) | xorg-server 2:1.16.4-1 (bookworm) |
| x.org | x_server | <= 1.16.3 | — |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p6c2-6v8p-34j6: The ProcPutImage function in dix/dispatch
ghsa_unreviewed·2022-05-14
CVE-2015-3418 [HIGH] CWE-369 GHSA-p6c2-6v8p-34j6: The ProcPutImage function in dix/dispatch
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
OSV
CVE-2015-3418: The ProcPutImage function in dix/dispatch
osv·2016-12-13·CVSS 7.5
CVE-2015-3418 [HIGH] CVE-2015-3418: The ProcPutImage function in dix/dispatch
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
Red Hat
xorg-x11-server: divide-by-zero when checking image dimensions
vendor_redhat·2015-04-24·CVSS 7.5
CVE-2015-3418 [HIGH] CWE-369 xorg-x11-server: divide-by-zero when checking image dimensions
xorg-x11-server: divide-by-zero when checking image dimensions
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
A divide-by-zero flaw was found in the way the X.Org server checked the dimensions of certain images. An attacker could potentially crash the X.Org server by tricking a suitable X application into displaying a specially crafted image file.
Package: xorg-x11-server (Red Hat Enterprise Linux 5) - Will not fix
Package: xorg-x11-server (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-3418: xorg-server - The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xor...
vendor_debian·2015·CVSS 7.5
CVE-2015-3418 [HIGH] CVE-2015-3418: xorg-server - The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xor...
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
Scope: local
bookworm: resolved (fixed in 2:1.16.4-1)
bullseye: resolved (fixed in 2:1.16.4-1)
forky: resolved (fixed in 2:1.16.4-1)
sid: resolved (fixed in 2:1.16.4-1)
trixie: resolved (fixed in 2:1.16.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3418 xorg-x11-server: divide-by-zero when checking image dimensions
bugzilla·2015-04-28·CVSS 6.5
CVE-2015-3418 [MEDIUM] CVE-2015-3418 xorg-x11-server: divide-by-zero when checking image dimensions
CVE-2015-3418 xorg-x11-server: divide-by-zero when checking image dimensions
A divide-by-zero flaw was found in the way the X.Org server checked the dimensions of certain images. An attacker may be able to crash the X.Org server by tricking a suitable X application into displaying a specially crafted image file.
This was introduced by the fix for the CVE-2014-8092 issue.
Upstream patch:
http://cgit.freedesktop.org/xorg/xserver/commit/?id=dc777c346d5d452a53b13b917c45f6a1bad2f20b
Discussion:
Created xorg-x11-server tracking bugs for this issue:
Affects: fedora-all [bug 1216022]
---
Although a malicious authenticated client could exploit this flaw to crash the X.Org server, this does not really cross any security boundaries, as X.Org provides other, intended mechanisms with the same
Bugzilla
CVE-2015-3418 xorg-x11-server: divide-by-zero when calculating image height [fedora-all]
bugzilla·2015-04-28·CVSS 7.5
CVE-2015-3418 [HIGH] CVE-2015-3418 xorg-x11-server: divide-by-zero when calculating image height [fedora-all]
CVE-2015-3418 xorg-x11-server: divide-by-zero when calculating image height [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74328https://cgit.freedesktop.org/xorg/xserver/commit/?id=dc777c346d5d452a53b13b917c45f6a1bad2f20bhttps://lists.x.org/archives/xorg-announce/2015-February/002532.htmlhttps://security.gentoo.org/glsa/201701-64http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74328https://cgit.freedesktop.org/xorg/xserver/commit/?id=dc777c346d5d452a53b13b917c45f6a1bad2f20bhttps://lists.x.org/archives/xorg-announce/2015-February/002532.htmlhttps://security.gentoo.org/glsa/201701-64
2016-12-13
Published