Heap
17-06-08, 20:50
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2361)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2361)