The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
https://bugs.freedesktop.org/show_bug.cgi?id=28801
http://www.openwall.com/lists/oss-security/2011/09/23/5
http://www.openwall.com/lists/oss-security/2011/09/22/8
http://securitytracker.com/id?1026149
http://rhn.redhat.com/errata/RHSA-2011-1360.html
http://rhn.redhat.com/errata/RHSA-2011-1359.html
http://aix.software.ibm.com/aix/efixes/security/X_advisory2.asc