PT-2013-1126 · X.Org+3 · Libxi+31

Ilja Van Sprundel

·

Published

2013-06-15

·

Updated

2024-06-15

·

CVE-2013-1995

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libX11 versions 1.6.0 libX11-devel versions 1.6.0 libXext versions 1.3.2 libXext-devel versions 1.3.2 libXfixes versions 5.0.1 libXfixes-devel versions 5.0.1 libXinerama versions 1.1.3 libXinerama-devel versions 1.1.3 libXi versions 1.7.2 libXi-devel versions 1.7.2 libXp versions 1.0.2 libXp-devel versions 1.0.2 libXrandr versions 1.4.1 libXrandr-devel versions 1.4.1 libXres versions 1.0.7 libXres-devel versions 1.0.7 libXt versions 1.1.4 libXt-devel versions 1.1.4 libXtst versions 1.2.2 libXtst-debuginfo versions 1.2.2 libXv versions 1.0.9 libXvMC versions 1.0.8 libXxf86dga versions 1.1.4 libXxf86vm versions 1.1.3 xorg-server versions prior to 1.14.3-r2 xorg-x11-proto-devel versions 7.7 xorg-x11-xtrans-devel versions 1.3.4 xcb-proto versions 1.8 xkeyboard-config versions 2.11
Description The issue is related to multiple vulnerabilities in various packages of the Red Hat Enterprise Linux and Gentoo Linux operating systems. These vulnerabilities can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely. The X.org libXi 1.7.1 and earlier versions are also affected, allowing X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.
Recommendations For libX11 versions 1.6.0, update to a newer version. For libX11-devel versions 1.6.0, update to a newer version. For libXext versions 1.3.2, update to a newer version. For libXext-devel versions 1.3.2, update to a newer version. For libXfixes versions 5.0.1, update to a newer version. For libXfixes-devel versions 5.0.1, update to a newer version. For libXinerama versions 1.1.3, update to a newer version. For libXinerama-devel versions 1.1.3, update to a newer version. For libXi versions 1.7.2, update to a newer version. For libXi-devel versions 1.7.2, update to a newer version. For libXp versions 1.0.2, update to a newer version. For libXp-devel versions 1.0.2, update to a newer version. For libXrandr versions 1.4.1, update to a newer version. For libXrandr-devel versions 1.4.1, update to a newer version. For libXres versions 1.0.7, update to a newer version. For libXres-devel versions 1.0.7, update to a newer version. For libXt versions 1.1.4, update to a newer version. For libXt-devel versions 1.1.4, update to a newer version. For libXtst versions 1.2.2, update to a newer version. For libXtst-debuginfo versions 1.2.2, update to a newer version. For libXv versions 1.0.9, update to a newer version. For libXvMC versions 1.0.8, update to a newer version. For libXxf86dga versions 1.1.4, update to a newer version. For libXxf86vm versions 1.1.3, update to a newer version. For xorg-server versions prior to 1.14.3-r2, update to version 1.14.3-r2 or later. For xorg-x11-proto-devel versions 7.7, update to a newer version. For xorg-x11-xtrans-devel versions 1.3.4, update to a newer version. For xcb-proto versions 1.8, update to a newer version. For xkeyboard-config versions 2.11, update to a newer version.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03351
BDU:2015-06306
BDU:2015-06354
BDU:2015-06355
BDU:2015-06356
BDU:2015-06357
BDU:2015-06358
BDU:2015-06359
BDU:2015-06360
BDU:2015-06361
BDU:2015-06362
BDU:2015-06363
BDU:2015-06364
BDU:2015-06365
BDU:2015-06366
BDU:2015-06367
BDU:2015-06375
BDU:2015-06376
BDU:2015-06377
BDU:2015-06378
BDU:2015-06379
BDU:2015-06380
BDU:2015-06392
BDU:2015-06393
BDU:2015-06394
BDU:2015-06395
BDU:2015-06396
BDU:2015-06397
BDU:2015-06398
BDU:2015-06399
BDU:2015-06400
BDU:2015-06401
BDU:2015-06402
BDU:2015-06403
BDU:2015-06404
BDU:2015-06405
BDU:2015-06406
BDU:2015-06407
BDU:2015-06408
BDU:2015-06409
BDU:2015-06410
BDU:2015-06411
BDU:2015-06412
BDU:2015-06575
BDU:2015-06576
BDU:2015-06577
BDU:2015-06607
BDU:2015-09727
CESA-2014_1436
CVE-2013-1995
DSA-2683-1
MGASA-2013-0186
OPENSUSE-SU-2024:10376-1
RHSA-2014:1436
RHSA-2014_1436
SUSE-SU-2015:0674-1

Affected Products

Centos
Red Hat
Suse
Libx11
Libx11-Devel
Libxext
Libxext-Dev
Libxfixes
Libxfixes-Devel
Libxi
Libxi-Devel
Libxinerama
Libxinerama-Devel
Libxp
Libxp-Devel
Libxrandr
Libxrandr-Dev
Libxres
Libxres-Devel
Libxt
Libxt-Devel
Libxtst
Libxtst-Debuginfo
Libxv
Libxvmc
Libxxf86Dga
Libxxf86Vm
Xcb-Proto
Xkeyboard-Config
Xorg-Server
Xorg-X11-Proto-Devel
Xorg-X11-Xtrans-Devel