CVE-2008-2361

Xorg X11 - Numeric Error

Title source: rule

Description

Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.

Scores

EPSS 0.0148
EPSS Percentile 80.7%

Classification

CWE
CWE-189
Status draft

Affected Products (1)

xorg/x11

Timeline

Published Jun 16, 2008
Tracked Since Feb 18, 2026