CVE-2013-1982

MEDIUM

Description

Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XcupGetReservedColormapEntries, (2) XcupStoreColors, (3) XdbeGetVisualInfo, (4) XeviGetVisualInfo, (5) XShapeGetRectangles, and (6) XSyncListSystemCounters functions.

References

http://lists.opensuse.org/opensuse-updates/2013-06/msg00139.html

http://www.debian.org/security/2013/dsa-2682

http://www.openwall.com/lists/oss-security/2013/05/23/3

http://www.ubuntu.com/usn/USN-1857-1

http://www.x.org/wiki/Development/Security/Advisory-2013-05-23

Details

Source: MITRE

Published: 2013-06-15

Updated: 2013-06-21

Type: CWE-189

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (20 total)

IDNameProductFamilySeverity
99930Oracle Secure Global Desktop Multiple Vulnerabilities (April 2017 CPU) (SWEET32)NessusMisc.
high
86215HP-UX PHSS_43690 : s700_800 11.31 X/Motif Runtime PatchNessusHP-UX Local Security Checks
medium
86119HP-UX PHSS_44188 : s700_800 11.11 X/Motif Runtime Periodic PatchNessusHP-UX Local Security Checks
medium
86118HP-UX PHSS_44149 : s700_800 11.23 X/Motif Runtime PatchNessusHP-UX Local Security Checks
medium
80822Oracle Solaris Third-Party Patch Update : xorg (multiple_vulnerabilities_in_x_org1)NessusSolaris Local Security Checks
medium
79560Amazon Linux AMI : libX11 / libXcursor,libXfixes,libXi,libXrandr,libXrender,libXres,libXt,libXv,libXvMC,libXxf86dga,libXxf86vm,libdmx,xorg-x11-proto-devel (ALAS-2014-452)NessusAmazon Linux Local Security Checks
medium
79182CentOS 6 : libX11 / libXcursor / libXext / libXfixes / libXi / libXinerama / libXp / libXrandr / etc (CESA-2014:1436)NessusCentOS Local Security Checks
medium
78841Scientific Linux Security Update : X11 client libraries on SL6.x i386/x86_64 (20141014)NessusScientific Linux Local Security Checks
medium
78411RHEL 6 : X11 client libraries (RHSA-2014:1436)NessusRed Hat Local Security Checks
medium
78346Amazon Linux AMI : libXext (ALAS-2014-403)NessusAmazon Linux Local Security Checks
medium
75028openSUSE Security Update : libXext (openSUSE-SU-2013:1009-1)NessusSuSE Local Security Checks
medium
74028GLSA-201405-07 : X.Org X Server: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
69113SuSE 11.3 Security Update : xorg-x11-libXext (SAT Patch Number 7931)NessusSuSE Local Security Checks
medium
67266Fedora 19 : libXext-1.3.2-1.fc19 (2013-10063)NessusFedora Local Security Checks
medium
67256SuSE 10 Security Update : xorg-x11 (ZYPP Patch Number 8623)NessusSuSE Local Security Checks
medium
67108SuSE 11.2 Security Update : xorg-x11-libXext (SAT Patch Number 7800)NessusSuSE Local Security Checks
medium
66821Ubuntu 10.04 LTS / 12.04 LTS / 12.10 / 13.04 : libxext vulnerability (USN-1857-1)NessusUbuntu Local Security Checks
medium
66798FreeBSD : xorg -- protocol handling issues in X Window System client libraries (2eebebff-cd3b-11e2-8f09-001b38c3836c)NessusFreeBSD Local Security Checks
medium
66753Fedora 18 : libXext-1.3.1-3.20130524gitdfe6e1f3b.fc18 (2013-9166)NessusFedora Local Security Checks
medium
66566Debian DSA-2682-1 : libxext - several vulnerabilitiesNessusDebian Local Security Checks
medium