CVE-2006-1526

Source
https://cve.org/CVERecord?id=CVE-2006-1526
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2006-1526.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2006-1526
Downstream
Published
2006-05-02T21:06:00Z
Modified
2025-08-09T19:01:27Z
Summary
[none]
Details

Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.

References

Affected packages