Multiple integer overflows in X.org libXrandr 1.4.0 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRRQueryOutputProperty and (2) XRRQueryProviderProperty functions.
| Software | From | Fixed in |
|---|---|---|
| x / libxrandr | 1.2.99.3 | 1.2.99.3.x |
| x / libxrandr | 1.3.1 | 1.3.1.x |
| x / libxrandr | 1.3.0 | 1.3.0.x |
| x / libxrandr | 1.2.3 | 1.2.3.x |
| x / libxrandr | - | 1.4.0.x |
| x / libxrandr | 1.2.99.1 | 1.2.99.1.x |
| x / libxrandr | 1.2.99.4 | 1.2.99.4.x |
| x / libxrandr | 1.3.2 | 1.3.2.x |
| x / libxrandr | 1.2.99.2 | 1.2.99.2.x |