PT-2013-1159 · Mesa+4 · Mesa-Libgl+6

Ilja Van Sprundel

·

Published

2013-06-03

·

Updated

2023-02-13

·

CVE-2013-1993

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mesa versions prior to 9.1.1 Mesa versions 6.5.1 Mesa-libGL versions 6.5.1 through 9.0 Mesa-libGLU versions 6.5.1 through 9.0 Mesa-libOSMesa versions 6.5.1 through 9.0 xorg-server versions prior to 1.14.3-r2
Description The issue is related to multiple integer overflows in X.org libGLX in Mesa, which can lead to the allocation of insufficient memory and a buffer overflow. This can be triggered by vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions. The vulnerability can be exploited remotely, potentially leading to a disruption of confidentiality, integrity, and availability of protected information.
Recommendations For Mesa versions prior to 9.1.1, update to version 9.1.1 or later. For Mesa versions 6.5.1, update to a newer version. For Mesa-libGL versions 6.5.1 through 9.0, update to version 9.0 or later. For Mesa-libGLU versions 6.5.1 through 9.0, update to version 9.0 or later. For Mesa-libOSMesa versions 6.5.1 through 9.0, update to version 9.0 or later. For xorg-server versions prior to 1.14.3-r2, update to version 1.14.3-r2 or later. As a temporary workaround, consider disabling the XF86DRIOpenConnection and XF86DRIGetClientDriverName functions until a patch is available.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-06201
BDU:2015-06418
BDU:2015-06419
BDU:2015-06420
BDU:2015-06421
BDU:2015-06422
BDU:2015-06423
BDU:2015-06424
BDU:2015-06425
BDU:2015-06426
BDU:2015-06427
BDU:2015-07232
BDU:2015-07420
BDU:2015-07421
BDU:2015-07422
BDU:2015-07423
BDU:2015-07424
BDU:2015-07425
BDU:2015-07426
BDU:2015-07427
BDU:2015-07428
BDU:2015-07429
BDU:2015-07430
BDU:2015-07431
BDU:2015-08994
BDU:2015-08995
BDU:2015-08996
BDU:2015-08997
BDU:2015-08998
BDU:2015-08999
BDU:2015-09000
BDU:2015-09001
BDU:2015-09002
BDU:2015-09003
BDU:2015-09011
BDU:2015-09012
BDU:2015-09013
BDU:2015-09014
BDU:2015-09015
BDU:2015-09016
BDU:2015-09017
BDU:2015-09018
BDU:2015-09019
BDU:2015-09020
BDU:2015-09021
BDU:2015-09727
CESA-2013_0897
CVE-2013-1993
DSA-2678-1
MGASA-2013-0186
MGASA-2013-0190
RHSA-2013:0897
RHSA-2013:0898
RHSA-2013_0897
RHSA-2013_0898
SUSE-SU-2013_1098-1
SUSE-SU-2013_1098-2
SUSE-SU-2014_0906-1

Affected Products

Centos
Mesa
Mesa-Libgl
Mesa-Libosmesa
Red Hat
Suse
Xorg-Server