CVE-2013-4396
EPSS 2.0%xorg-server - use-after-free
Published: 10/10/2013Modified: 4/28/2026
Also known as:DEBIAN-CVE-2013-4396
Description
Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.
Affected packages (2)
- Debian/xorg-serverfrom 0, < 2:1.14.3-4
- Debian/xorg-serverfrom 0, < 2:1.7.7-17