CVE-2010-4819

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
05/09/2012
Last modified:
11/04/2025

Description

The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:x:x.org-xserver:*:*:*:*:*:*:*:* 1.7.7 (including)
cpe:2.3:a:x:x.org-xserver:1.7:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org-xserver:1.7.6.902:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org-xserver:1.7.7:rc2:*:*:*:*:*:*