CVE-2013-4396: X X.org x11

Medium severity, CVSS 6.5. EPSS: 4.1% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.

Affected products

  • X X.org x11: version 6.0 only; version 6.1 only; version 6.3 only; version 6.4 only; version 6.5.1 only; version 6.6 only; …

Published 2013-10-10. Last modified 2026-06-16.