CVE-2013-4396

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
10/10/2013
Last modified:
11/04/2025

Description

Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:x:x.org_x11:6.0:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.1:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.3:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.4:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.6:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.7:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.8:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.8.1:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.8.2:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:6.9.0:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:7.0:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:7.1:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:7.2:*:*:*:*:*:*:*
cpe:2.3:a:x:x.org_x11:7.3:*:*:*:*:*:*:*