CVE-2013-2000

MEDIUM

Description

Multiple buffer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XDGAQueryModes and (2) XDGASetMode functions.

References

http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106870.html

http://www.debian.org/security/2013/dsa-2690

http://www.openwall.com/lists/oss-security/2013/05/23/3

http://www.ubuntu.com/usn/USN-1869-1

http://www.x.org/wiki/Development/Security/Advisory-2013-05-23

Details

Source: MITRE

Published: 2013-06-15

Updated: 2013-11-25

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
80819Oracle Solaris Third-Party Patch Update : xorg (multiple_vulnerabilities_in_x_org)NessusSolaris Local Security Checks
medium
79560Amazon Linux AMI : libX11 / libXcursor,libXfixes,libXi,libXrandr,libXrender,libXres,libXt,libXv,libXvMC,libXxf86dga,libXxf86vm,libdmx,xorg-x11-proto-devel (ALAS-2014-452)NessusAmazon Linux Local Security Checks
medium
79182CentOS 6 : libX11 / libXcursor / libXext / libXfixes / libXi / libXinerama / libXp / libXrandr / etc (CESA-2014:1436)NessusCentOS Local Security Checks
medium
78841Scientific Linux Security Update : X11 client libraries on SL6.x i386/x86_64 (20141014)NessusScientific Linux Local Security Checks
medium
78411RHEL 6 : X11 client libraries (RHSA-2014:1436)NessusRed Hat Local Security Checks
medium
75045openSUSE Security Update : libXxf86dga (openSUSE-SU-2013:1030-1)NessusSuSE Local Security Checks
medium
74028GLSA-201405-07 : X.Org X Server: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
69112SuSE 11.3 Security Update : xorg-x11-libs (SAT Patch Number 7944)NessusSuSE Local Security Checks
medium
67356Fedora 18 : libXxf86dga-1.1.3-5.20130524gita8dc6be32.fc18 (2013-9177)NessusFedora Local Security Checks
medium
67256SuSE 10 Security Update : xorg-x11 (ZYPP Patch Number 8623)NessusSuSE Local Security Checks
medium
67106SuSE 11.2 Security Update : xorg-x11-libs (SAT Patch Number 7846)NessusSuSE Local Security Checks
medium
66833Ubuntu 12.04 LTS / 12.10 / 13.04 : libxxf86dga vulnerabilities (USN-1869-1)NessusUbuntu Local Security Checks
medium
66798FreeBSD : xorg -- protocol handling issues in X Window System client libraries (2eebebff-cd3b-11e2-8f09-001b38c3836c)NessusFreeBSD Local Security Checks
medium
66628Fedora 19 : libXxf86dga-1.1.3-5.20130524gita8dc6be32.fc19 (2013-9085)NessusFedora Local Security Checks
medium
66574Debian DSA-2690-1 : libxxf86dga - several vulnerabilitiesNessusDebian Local Security Checks
medium