CVE-2014-8100

The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) ProcRenderQueryVersion, (2) SProcRenderQueryVersion, (3) SProcRenderQueryPictFormats, (4) SProcRenderQueryPictIndexValues, (5) SProcRenderCreatePicture, (6) SProcRenderChangePicture, (7) SProcRenderSetPictureClipRectangles, (8) SProcRenderFreePicture, (9) SProcRenderComposite, (10) SProcRenderScale, (11) SProcRenderCreateGlyphSet, (12) SProcRenderReferenceGlyphSet, (13) SProcRenderFreeGlyphSet, (14) SProcRenderFreeGlyphs, or (15) SProcRenderCompositeGlyphs function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
x.orgxfree86
4.0.1
x.orgx_server
𝑥
≤ 1.16.2.99.901
x.orgx11
6.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xorg-server
bookworm
2:21.1.7-3+deb12u7
fixed
bookworm (security)
2:21.1.7-3+deb12u8
fixed
bullseye
2:1.20.11-1+deb11u13
fixed
bullseye (security)
2:1.20.11-1+deb11u14
fixed
sid
2:21.1.14-1
fixed
trixie
2:21.1.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg-server
lucid
ignored
precise
Fixed 2:1.11.4-0ubuntu10.15
released
trusty
Fixed 2:1.15.1-0ubuntu2.4
released
utopic
Fixed 2:1.16.0-1ubuntu1.1
released
xorg-server-lts-trusty
lucid
dne
precise
Fixed 2:1.15.1-0ubuntu2~precise3
released
trusty
dne
utopic
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
xorg-x11-server
suse enterprise sap 12 SP5
1.19.6-8.18
fixed
suse enterprise server 12 SP5
1.19.6-8.18
fixed
xorg-x11-server-extra
suse enterprise sap 12 SP5
1.19.6-8.18
fixed
suse enterprise server 12 SP5
1.19.6-8.18
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
xorg-x11-server-Xdmx
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed
xorg-x11-server-Xephyr
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed
xorg-x11-server-Xnest
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed
xorg-x11-server-Xorg
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed
xorg-x11-server-Xvfb
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed
xorg-x11-server-common
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed
xorg-x11-server-devel
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed
xorg-x11-server-source
RHEL 6
0:1.15.0-25.el6_6
fixed
RHEL 7
0:1.15.0-7.el7_0.3
fixed