Multiple integer overflows in X.org libXRes 1.0.6 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XResQueryClients and (2) XResQueryClientResources functions.
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106880.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00155.html
http://www.debian.org/security/2013/dsa-2688
http://www.openwall.com/lists/oss-security/2013/05/23/3
http://www.ubuntu.com/usn/USN-1864-1
http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
OR
cpe:2.3:a:x:libxres:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:x:libxres:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:x:libxres:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:x:libxres:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:x:libxres:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:x:libxres:*:*:*:*:*:*:*:* versions up to 1.0.6 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
103943 | Slackware 14.1 / 14.2 / current : libXres (SSA:2017-291-01) | Nessus | Slackware Local Security Checks | medium |
80819 | Oracle Solaris Third-Party Patch Update : xorg (multiple_vulnerabilities_in_x_org) | Nessus | Solaris Local Security Checks | medium |
79560 | Amazon Linux AMI : libX11 / libXcursor,libXfixes,libXi,libXrandr,libXrender,libXres,libXt,libXv,libXvMC,libXxf86dga,libXxf86vm,libdmx,xorg-x11-proto-devel (ALAS-2014-452) | Nessus | Amazon Linux Local Security Checks | medium |
79182 | CentOS 6 : libX11 / libXcursor / libXext / libXfixes / libXi / libXinerama / libXp / libXrandr / etc (CESA-2014:1436) | Nessus | CentOS Local Security Checks | medium |
78841 | Scientific Linux Security Update : X11 client libraries on SL6.x i386/x86_64 (20141014) | Nessus | Scientific Linux Local Security Checks | medium |
78411 | RHEL 6 : X11 client libraries (RHSA-2014:1436) | Nessus | Red Hat Local Security Checks | medium |
75042 | openSUSE Security Update : libXres (openSUSE-SU-2013:1027-1) | Nessus | SuSE Local Security Checks | medium |
74028 | GLSA-201405-07 : X.Org X Server: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | medium |
69112 | SuSE 11.3 Security Update : xorg-x11-libs (SAT Patch Number 7944) | Nessus | SuSE Local Security Checks | medium |
67256 | SuSE 10 Security Update : xorg-x11 (ZYPP Patch Number 8623) | Nessus | SuSE Local Security Checks | medium |
67106 | SuSE 11.2 Security Update : xorg-x11-libs (SAT Patch Number 7846) | Nessus | SuSE Local Security Checks | medium |
66828 | Ubuntu 12.04 LTS / 12.10 / 13.04 : libxres vulnerability (USN-1864-1) | Nessus | Ubuntu Local Security Checks | medium |
66798 | FreeBSD : xorg -- protocol handling issues in X Window System client libraries (2eebebff-cd3b-11e2-8f09-001b38c3836c) | Nessus | FreeBSD Local Security Checks | medium |
66751 | Fedora 18 : libXres-1.0.6-5.20130524gitf46818496.fc18 (2013-9141) | Nessus | Fedora Local Security Checks | medium |
66624 | Fedora 19 : libXres-1.0.6-5.20130524gitf46818496.fc19 (2013-9060) | Nessus | Fedora Local Security Checks | medium |
66572 | Debian DSA-2688-1 : libxres - several vulnerabilities | Nessus | Debian Local Security Checks | medium |