Buffer overflow in xcmsdb - CVE-2013-2005

 

Buffer overflow in xcmsdb - CVE-2013-2005

Published: June 15, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32668
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2005
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.


Affected software

xcmsdb
HP-UX
Amazon Linux AMI
libxt (Alpine package)

How to mitigate CVE-2013-2005

Install update from vendor's website.

xcmsdb - update to 1.1.4
libxt (Alpine package) - update to 1.1.3-r1

External References

Related Security Bulletins