LOW
security flaw
Published May 2, 2006
2.1
LOWCVSS 2.0
EPSS 0.51%
Description
Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.
Affected products
No data.
No data.
Red Hat Enterprise Linux 4
xorg-x11-0:6.8.2-1.EL.13.25.1
Fixed · RHSA-2006:0451
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | xorg-x11-0:6.8.2-1.EL.13.25.1 | Fixed | RHSA-2006:0451 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (29)
- http://lists.freedesktop.org/archives/xorg/2006-May/015136.html mailing-listx_refsource_MLISTPatch
- http://secunia.com/advisories/19900 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19915 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19916 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19921 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19943 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19951 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19956 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19983 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1016018 vdb-entryx_refsource_SECTRACK
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102339-1 vendor-advisoryx_refsource_SUNALERT
- http://www.gentoo.org/security/en/glsa/glsa-200605-02.xml vendor-advisoryx_refsource_GENTOOPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/633257 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:081 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_05_03.html vendor-advisoryx_refsource_SUSEPatchVendor Advisory
- http://www.openbsd.org/errata38.html#xorg vendor-advisoryx_refsource_OPENBSD
- http://www.redhat.com/support/errata/RHSA-2006-0451.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://www.securityfocus.com/archive/1/436327/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/17795 vdb-entryx_refsource_BID
- http://www.trustix.org/errata/2006/0024 vendor-advisoryx_refsource_TRUSTIX
- http://www.vupen.com/english/advisories/2006/1617 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-1526 Vendor Advisory
- https://bugs.freedesktop.org/show_bug.cgi?id=6642 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1618042 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26200 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-1526
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9929 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/280-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-1526
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 2, 2006
Updated Aug 7, 2024
Reserved Mar 30, 2006
Link CVE-2006-1526
CISA Vulnrichment
Updated n/a