Numeric Errors The advisory has been revoked - it doesn't affect any version of package xorg-server  (opens in a new tab)


Threat Intelligence

EPSS
3.28% (92nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN11-XORGSERVER-607370
  • published19 Aug 2020
  • disclosed29 Apr 2010

Introduced: 29 Apr 2010

CVE-2010-1166  (opens in a new tab)
CWE-189  (opens in a new tab)

Amendment

The Debian security team deemed this advisory irrelevant for Debian:11.

NVD Description

Note: Versions mentioned in the description apply only to the upstream xorg-server package and not the xorg-server package as distributed by Debian.

The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.