Unrated severityNVD Advisory· Published May 2, 2006· Updated Apr 16, 2026
CVE-2006-1526
CVE-2006-1526
Description
Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
25- lists.freedesktop.org/archives/xorg/2006-May/015136.htmlnvdPatch
- secunia.com/advisories/19900nvdPatchVendor Advisory
- secunia.com/advisories/19915nvdPatchVendor Advisory
- secunia.com/advisories/19916nvdPatchVendor Advisory
- secunia.com/advisories/19921nvdPatchVendor Advisory
- secunia.com/advisories/19943nvdPatchVendor Advisory
- secunia.com/advisories/19951nvdPatchVendor Advisory
- secunia.com/advisories/19956nvdPatchVendor Advisory
- www.gentoo.org/security/en/glsa/glsa-200605-02.xmlnvdPatchVendor Advisory
- www.novell.com/linux/security/advisories/2006_05_03.htmlnvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2006-0451.htmlnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/633257nvdUS Government Resource
- secunia.com/advisories/19983nvd
- securitytracker.com/idnvd
- sunsolve.sun.com/search/document.donvd
- www.mandriva.com/security/advisoriesnvd
- www.openbsd.org/errata38.htmlnvd
- www.securityfocus.com/archive/1/436327/100/0/threadednvd
- www.securityfocus.com/bid/17795nvd
- www.trustix.org/errata/2006/0024nvd
- www.vupen.com/english/advisories/2006/1617nvd
- bugs.freedesktop.org/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/26200nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9929nvd
- usn.ubuntu.com/280-1/nvd
News mentions
0No linked articles in our index yet.