CVE-2013-1997

Public on 2013-06-15
Modified on 2014-11-24
Description
Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4) _XkbReadGetGeometryReply, (5) _XkbReadKeySyms, (6) _XkbReadKeyActions, (7) _XkbReadKeyBehaviors, (8) _XkbReadModifierMap, (9) _XkbReadExplicitComponents, (10) _XkbReadVirtualModMap, (11) _XkbReadGetNamesReply, (12) _XkbReadGetMapReply, (13) _XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.
Severity
Medium severity
Medium
CVSS v3 Base Score
4.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 libX11 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXcursor 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXfixes 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXi 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXrandr 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXrender 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXres 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXt 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXv 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXvMC 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXxf86dga 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libXxf86vm 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 libdmx 2014-11-22 ALAS-2014-452 Fixed
Amazon Linux 1 xorg-x11-proto-devel 2014-11-22 ALAS-2014-452 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 4.3 AV:A/AC:H/Au:N/C:P/I:P/A:P
NVD CVSSv2 6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P