CVE-2013-1987

MEDIUM

Description

Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.

References

http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106862.html

http://lists.opensuse.org/opensuse-updates/2013-06/msg00141.html

http://www.debian.org/security/2013/dsa-2677

http://www.openwall.com/lists/oss-security/2013/05/23/3

http://www.securityfocus.com/bid/60132

http://www.ubuntu.com/usn/USN-1863-1

http://www.x.org/wiki/Development/Security/Advisory-2013-05-23

Details

Source: MITRE

Published: 2013-06-15

Updated: 2018-10-30

Type: CWE-189

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
99930Oracle Secure Global Desktop Multiple Vulnerabilities (April 2017 CPU) (SWEET32)NessusMisc.
high
80819Oracle Solaris Third-Party Patch Update : xorg (multiple_vulnerabilities_in_x_org)NessusSolaris Local Security Checks
medium
79560Amazon Linux AMI : libX11 / libXcursor,libXfixes,libXi,libXrandr,libXrender,libXres,libXt,libXv,libXvMC,libXxf86dga,libXxf86vm,libdmx,xorg-x11-proto-devel (ALAS-2014-452)NessusAmazon Linux Local Security Checks
medium
79182CentOS 6 : libX11 / libXcursor / libXext / libXfixes / libXi / libXinerama / libXp / libXrandr / etc (CESA-2014:1436)NessusCentOS Local Security Checks
medium
78841Scientific Linux Security Update : X11 client libraries on SL6.x i386/x86_64 (20141014)NessusScientific Linux Local Security Checks
medium
78411RHEL 6 : X11 client libraries (RHSA-2014:1436)NessusRed Hat Local Security Checks
medium
75030openSUSE Security Update : libXrender (openSUSE-SU-2013:1011-1)NessusSuSE Local Security Checks
medium
74028GLSA-201405-07 : X.Org X Server: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
69115SuSE 11.3 Security Update : xorg-x11-libXrender (SAT Patch Number 7939)NessusSuSE Local Security Checks
medium
67256SuSE 10 Security Update : xorg-x11 (ZYPP Patch Number 8623)NessusSuSE Local Security Checks
medium
67111SuSE 11.2 Security Update : xorg-x11-libXrender (SAT Patch Number 7809)NessusSuSE Local Security Checks
medium
66827Ubuntu 10.04 LTS / 12.04 LTS / 12.10 / 13.04 : libxrender vulnerability (USN-1863-1)NessusUbuntu Local Security Checks
medium
66798FreeBSD : xorg -- protocol handling issues in X Window System client libraries (2eebebff-cd3b-11e2-8f09-001b38c3836c)NessusFreeBSD Local Security Checks
medium
66743Fedora 18 : libXrender-0.9.7-5.20130524git786f78fd8.fc18 (2013-9107)NessusFedora Local Security Checks
medium
66621Fedora 19 : libXrender-0.9.7-5.20130524git786f78fd8.fc19 (2013-9052)NessusFedora Local Security Checks
medium
66561Debian DSA-2677-1 : libxrender - several vulnerabilitiesNessusDebian Local Security Checks
medium