CVE-2010-4819

NameCVE-2010-4819
DescriptionThe ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xorg-server (PTS)buster2:1.20.4-1+deb10u4fixed
buster (security)2:1.20.4-1+deb10u14fixed
bullseye2:1.20.11-1+deb11u11fixed
bullseye (security)2:1.20.11-1+deb11u13fixed
bookworm2:21.1.7-3+deb12u5fixed
bookworm (security)2:21.1.7-3+deb12u7fixed
sid, trixie2:21.1.12-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xorg-serversourcesqueeze2:1.7.7-14
xorg-serversource(unstable)2:1.9.0.901-1

Notes

[lenny] - xorg-server <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems