Alpine: multiple libx11 packages: security update to 1.5.0-r0 (deprecated)

high Tenable Cloud Security Plugin ID 401240

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger
allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2)
_XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6)
XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeyboardMapping, (9) XGetWindowProperty, (10)
XGetImage, (11) LoadColornameDB, (12) XrmGetFileDatabase, (13) _XimParseStringFile, or (14) TransFileName
functions. (CVE-2013-1981)

- Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a
denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the
(1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4)
_XkbReadGetGeometryReply, (5) _XkbReadKeySyms, (6) _XkbReadKeyActions, (7) _XkbReadKeyBehaviors, (8)
_XkbReadModifierMap, (9) _XkbReadExplicitComponents, (10) _XkbReadVirtualModMap, (11)
_XkbReadGetNamesReply, (12) _XkbReadGetMapReply, (13) _XimXGetReadData, (14) XListFonts, (15)
XListExtensions, and (16) XGetFontPath functions. (CVE-2013-1997)

- The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier
do not restrict the recursion depth when processing directives to include files, which allows X servers to
cause a denial of service (stack consumption) via a crafted file. (CVE-2013-2004)

See Also

https://git.alpinelinux.org/aports/commit/?id=29cd7b42af8cddcb339f1328bf8f7be3a115b396

https://git.alpinelinux.org/aports/commit/?id=682ed1fa3f5d7338fff3b497e1b95d45b2481e79

Plugin Details

Severity: High

ID: 401240

Version: Revision 1.24

Type: Local

Published: 8/16/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2013-2004

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2013-1981

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/24/2013

Vulnerability Publication Date: 5/23/2013

Reference Information

CVE: CVE-2013-1981, CVE-2013-1997, CVE-2013-2004

BID: 60120, 60122, 60146