CVE-2007-2437

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2007
Last modified:
09/04/2025

Description

The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:x.org:x_window_system:7.0:*:*:*:*:*:*:*
cpe:2.3:a:x.org:x_window_system:7.1:*:*:*:*:*:*:*
cpe:2.3:a:x.org:x_window_system:7.2:*:*:*:*:*:*:*
cpe:2.3:a:x.org:xserver:*:*:*:*:*:*:*:* 1.3.0 (including)