Vulnerability Description
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| X.Org | X Window System | 7.0 |
| X.Org | Xserver | <= 1.3.0 |
References
- http://osvdb.org/34905
- http://secunia.com/advisories/25121
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102901-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200067-1
- http://www.rapid7.com/advisories/R7-0027.jspPatch
- http://www.securityfocus.com/bid/23741
- http://www.securitytracker.com/id?1017984Patch
- http://www.vupen.com/english/advisories/2007/1601
- http://www.vupen.com/english/advisories/2007/1658
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33976
- http://osvdb.org/34905
- http://secunia.com/advisories/25121
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102901-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200067-1
- http://www.rapid7.com/advisories/R7-0027.jspPatch
FAQ
What is CVE-2007-2437?
CVE-2007-2437 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted v...
How severe is CVE-2007-2437?
CVE-2007-2437 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2437?
Check the references section above for vendor advisories and patch information. Affected products include: X.Org X Window System, X.Org Xserver.