CVE-2013-1992

MEDIUM

Description

Multiple integer overflows in X.org libdmx 1.1.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) DMXGetScreenAttributes, (2) DMXGetWindowAttributes, and (3) DMXGetInputAttributes functions.

References

http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107024.html

http://lists.opensuse.org/opensuse-updates/2013-06/msg00157.html

http://www.debian.org/security/2013/dsa-2673

http://www.openwall.com/lists/oss-security/2013/05/23/3

http://www.ubuntu.com/usn/USN-1852-1

http://www.x.org/wiki/Development/Security/Advisory-2013-05-23

Details

Source: MITRE

Published: 2013-06-15

Updated: 2013-11-25

Type: CWE-189

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (13 total)

IDNameProductFamilySeverity
80819Oracle Solaris Third-Party Patch Update : xorg (multiple_vulnerabilities_in_x_org)NessusSolaris Local Security Checks
medium
79182CentOS 6 : libX11 / libXcursor / libXext / libXfixes / libXi / libXinerama / libXp / libXrandr / etc (CESA-2014:1436)NessusCentOS Local Security Checks
medium
78411RHEL 6 : X11 client libraries (RHSA-2014:1436)NessusRed Hat Local Security Checks
medium
75046openSUSE Security Update : libdmx (openSUSE-SU-2013:1029-1)NessusSuSE Local Security Checks
medium
74028GLSA-201405-07 : X.Org X Server: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
69112SuSE 11.3 Security Update : xorg-x11-libs (SAT Patch Number 7944)NessusSuSE Local Security Checks
medium
67256SuSE 10 Security Update : xorg-x11 (ZYPP Patch Number 8623)NessusSuSE Local Security Checks
medium
67106SuSE 11.2 Security Update : xorg-x11-libs (SAT Patch Number 7846)NessusSuSE Local Security Checks
medium
66816Ubuntu 12.04 LTS / 12.10 / 13.04 : libdmx vulnerability (USN-1852-1)NessusUbuntu Local Security Checks
medium
66798FreeBSD : xorg -- protocol handling issues in X Window System client libraries (2eebebff-cd3b-11e2-8f09-001b38c3836c)NessusFreeBSD Local Security Checks
medium
66745Fedora 18 : libdmx-1.1.2-4.20130524git5074d9d64.fc18 (2013-9115)NessusFedora Local Security Checks
medium
66658Fedora 19 : libdmx-1.1.2-4.20130524git5074d9d64.fc19 (2013-9078)NessusFedora Local Security Checks
medium
66557Debian DSA-2673-1 : libdmx - several vulnerabilitiesNessusDebian Local Security Checks
medium