Date: Fri, 24 Apr 2015 17:00:22 +0200 From: Marcus Meissner <meissner@...e.de> To: OSS Security List <oss-security@...ts.openwall.com>, xorg_security@...rg Cc: cve-assign@...re.org Subject: CVE request: X server crash by client Hi, We got notified that the fix for CVE-2014-8092 introduced the possibility of a division by 0 when the "height" for the PutImage call is 0, leading to X server abort. https://bugzilla.novell.com/show_bug.cgi?id=928520 This was already fixed in January in X git. http://cgit.freedesktop.org/xorg/xserver/commit/?id=dc777c346d5d452a53b13b917c45f6a1bad2f20b As this is a local denial of service, but might be triggerable by images with 0 height supplied externally, it might need a CVE. Ciao, Marcus
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.