CVE-2008-2361

Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.

Date published : 2008-06-16

http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html

http://www.securityfocus.com/bid/29665