CVE-2007-2437
EPSS 3.8%
Description
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.
How to fix CVE-2007-2437
To remediate CVE-2007-2437, upgrade the affected package to a fixed version below.
- Debian/xorg-server—upgrade to 2:1.3.0.0.dfsg-4 or later
Is CVE-2007-2437 being exploited?
Low — EPSS is 3.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:1.3.0.0.dfsg-4