PT-2013-1064 · X.Org+3 · Libxi+21

Ilja Van Sprundel

·

Published

2013-06-15

·

Updated

2024-06-15

·

CVE-2013-1981

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libX11 versions 1.5.99.901 through 1.6.0 libXext versions 1.3.2 libXt versions 1.1.4 libXfixes versions 5.0.1 libXinerama versions 1.1.3 xorg-x11-proto-devel version 7.7 libXp versions 1.0.2 libXtst versions 1.2.2 libXi versions 1.7.2 libXres versions 1.0.7 libXrandr versions 1.4.1 libXv versions 1.0.9 libXvMC versions 1.0.8 libXcursor versions 1.1.14 libXrender versions 0.9.8 libXxf86vm versions 1.1.3 libXxf86dga versions 1.1.4 xcb-proto version 1.8 xorg-server versions prior to 1.14.3-r2
Description The issue is related to multiple vulnerabilities in various packages of the X.org library, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The affected packages include libX11, libXext, libXt, libXfixes, libXinerama, xorg-x11-proto-devel, libXp, libXtst, libXi, libXres, libXrandr, libXv, libXvMC, libXcursor, libXrender, libXxf86vm, libXxf86dga, and xcb-proto. The vulnerabilities are caused by multiple integer overflows in the X.org libX11 library, which can trigger allocation of insufficient memory and a buffer overflow via various vectors, including the XQueryFont, XF86BigfontQueryFont, XListFontsWithInfo, XGetMotionEvents, XListHosts, XGetModifierMapping, XGetPointerMapping, XGetKeyboardMapping, XGetWindowProperty, XGetImage, LoadColornameDB, XrmGetFileDatabase, XimParseStringFile, and TransFileName functions.
Recommendations For libX11 versions 1.5.99.901 through 1.6.0, update to a version later than 1.6.0. For libXext versions 1.3.2, update to a version later than 1.3.2. For libXt versions 1.1.4, update to a version later than 1.1.4. For libXfixes versions 5.0.1, update to a version later than 5.0.1. For libXinerama versions 1.1.3, update to a version later than 1.1.3. For xorg-x11-proto-devel version 7.7, update to a version later than 7.7. For libXp versions 1.0.2, update to a version later than 1.0.2. For libXtst versions 1.2.2, update to a version later than 1.2.2. For libXi versions 1.7.2, update to a version later than 1.7.2. For libXres versions 1.0.7, update to a version later than 1.0.7. For libXrandr versions 1.4.1, update to a version later than 1.4.1. For libXv versions 1.0.9, update to a version later than 1.0.9. For libXvMC versions 1.0.8, update to a version later than 1.0.8. For libXcursor versions 1.1.14, update to a version later than 1.1.14. For libXrender versions 0.9.8, update to a version later than 0.9.8. For libXxf86vm versions 1.1.3, update to a version later than 1.1.3. For libXxf86dga versions 1.1.4, update to a version later than 1.1.4. For xcb-proto version 1.8, update to a version later than 1.8. For xorg-server versions prior to 1.14.3-r2, update to version 1.14.3-r2 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01795
BDU:2015-06306
BDU:2015-06354
BDU:2015-06355
BDU:2015-06356
BDU:2015-06357
BDU:2015-06358
BDU:2015-06359
BDU:2015-06360
BDU:2015-06361
BDU:2015-06362
BDU:2015-06363
BDU:2015-06364
BDU:2015-06365
BDU:2015-06366
BDU:2015-06367
BDU:2015-06375
BDU:2015-06376
BDU:2015-06377
BDU:2015-06378
BDU:2015-06379
BDU:2015-06380
BDU:2015-06392
BDU:2015-06393
BDU:2015-06394
BDU:2015-06395
BDU:2015-06396
BDU:2015-06397
BDU:2015-06398
BDU:2015-06399
BDU:2015-06400
BDU:2015-06401
BDU:2015-06402
BDU:2015-06403
BDU:2015-06404
BDU:2015-06405
BDU:2015-06406
BDU:2015-06407
BDU:2015-06408
BDU:2015-06409
BDU:2015-06410
BDU:2015-06411
BDU:2015-06412
BDU:2015-06575
BDU:2015-06576
BDU:2015-06577
BDU:2015-06607
BDU:2015-09727
CESA-2014_1436
CVE-2013-1981
DSA-2693-1
MGASA-2013-0186
OPENSUSE-SU-2024:10395-1
RHSA-2014:1436
RHSA-2014_1436
SUSE-SU-2013_1100-1
SUSE-SU-2013_1100-2
SUSE-SU-2013_1183-1
SUSE-SU-2014_0893-1

Affected Products

Centos
Red Hat
Suse
Libx11
Libxcursor
Libxext
Libxfixes
Libxi
Libxinerama
Libxp
Libxrandr
Libxrender
Libxres
Libxt
Libxtst
Libxv
Libxvmc
Libxxf86Dga
Libxxf86Vm
Xcb-Proto
Xorg-Server
Xorg-X11-Proto-Devel