PT-2013-1114 · X.Org+3 · Libxi+19
Ilja Van Sprundel
·
Published
2013-06-15
·
Updated
2014-10-20
·
CVE-2013-1988
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libXres versions 1.0.7 and earlier
libX11 versions 1.6.0 and earlier
libXext versions 1.3.2 and earlier
libXt versions 1.1.4 and earlier
libXtst versions 1.2.2 and earlier
libXi versions 1.7.2 and earlier
libXrandr versions 1.4.1 and earlier
libXv versions 1.0.9 and earlier
libXvMC versions 1.0.8 and earlier
libXcursor versions 1.1.14 and earlier
libXfixes versions 5.0.1 and earlier
libXinerama versions 1.1.3 and earlier
libXrender versions 0.9.8 and earlier
libXxf86dga versions 1.1.4 and earlier
libXxf86vm versions 1.1.3 and earlier
xorg-server versions prior to 1.14.3-r2
xcb-proto versions 1.8 and earlier
Description
The issue is related to multiple vulnerabilities in various packages of the X.org library, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are caused by multiple integer overflows in the X.org libXRes library, allowing X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XResQueryClients and XResQueryClientResources functions.
Recommendations
For libXres versions 1.0.7 and earlier, update to a version later than 1.0.7.
For libX11 versions 1.6.0 and earlier, update to a version later than 1.6.0.
For libXext versions 1.3.2 and earlier, update to a version later than 1.3.2.
For libXt versions 1.1.4 and earlier, update to a version later than 1.1.4.
For libXtst versions 1.2.2 and earlier, update to a version later than 1.2.2.
For libXi versions 1.7.2 and earlier, update to a version later than 1.7.2.
For libXrandr versions 1.4.1 and earlier, update to a version later than 1.4.1.
For libXv versions 1.0.9 and earlier, update to a version later than 1.0.9.
For libXvMC versions 1.0.8 and earlier, update to a version later than 1.0.8.
For libXcursor versions 1.1.14 and earlier, update to a version later than 1.1.14.
For libXfixes versions 5.0.1 and earlier, update to a version later than 5.0.1.
For libXinerama versions 1.1.3 and earlier, update to a version later than 1.1.3.
For libXrender versions 0.9.8 and earlier, update to a version later than 0.9.8.
For libXxf86dga versions 1.1.4 and earlier, update to a version later than 1.1.4.
For libXxf86vm versions 1.1.3 and earlier, update to a version later than 1.1.3.
For xorg-server versions prior to 1.14.3-r2, update to version 1.14.3-r2 or later.
For xcb-proto versions 1.8 and earlier, update to a version later than 1.8.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Libx11
Libxcursor
Libxext
Libxfixes
Libxi
Libxinerama
Libxrandr
Libxrender
Libxres
Libxt
Libxtst
Libxv
Libxvmc
Libxxf86Dga
Libxxf86Vm
Xcb-Proto
Xorg-Server