CVE-2010-4818

The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via (1) a crafted request that triggers a client swap in glx/glxcmdsswap.c; or (2) a crafted length or (3) a negative value in the screen field in a request to glx/glxcmds.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
x.orgx.org
1.7.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xorg-server
bookworm
2:21.1.7-3+deb12u7
fixed
bookworm (security)
2:21.1.7-3+deb12u8
fixed
bullseye
2:1.20.11-1+deb11u13
fixed
bullseye (security)
2:1.20.11-1+deb11u14
fixed
lenny
no-dsa
sid
2:21.1.14-1
fixed
trixie
2:21.1.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg-server
hardy
ignored
lucid
Fixed 2:1.7.6-2ubuntu7.10
released
maverick
Fixed 2:1.9.0-0ubuntu7.5
released
natty
not-affected
oneiric
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
xorg-x11-server-Xdmx
RHEL 6
0:1.7.7-29.el6_1.2
fixed
xorg-x11-server-Xephyr
RHEL 6
0:1.7.7-29.el6_1.2
fixed
xorg-x11-server-Xnest
RHEL 6
0:1.7.7-29.el6_1.2
fixed
xorg-x11-server-Xorg
RHEL 6
0:1.7.7-29.el6_1.2
fixed
xorg-x11-server-Xvfb
RHEL 6
0:1.7.7-29.el6_1.2
fixed
xorg-x11-server-common
RHEL 6
0:1.7.7-29.el6_1.2
fixed
xorg-x11-server-devel
RHEL 6
0:1.7.7-29.el6_1.2
fixed
xorg-x11-server-source
RHEL 6
0:1.7.7-29.el6_1.2
fixed