Buffer overflow in libxi - CVE-2013-1995
Published: June 15, 2013 / Updated: August 3, 2020
Vulnerability identifier: #VU33307
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1995
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.
Affected software
libxi
libxi (Alpine package)
Amazon Linux AMI
libxi (Alpine package)
Amazon Linux AMI
How to mitigate CVE-2013-1995
Install update from vendor's website.
libxi - update to 1.7.1.901
libxi (Alpine package) - update to 1.4.5-r1
libxi (Alpine package) - update to 1.4.5-r1
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106913.html
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00161.html
- http://www.debian.org/security/2013/dsa-2683
- http://www.openwall.com/lists/oss-security/2013/05/23/3
- http://www.securityfocus.com/bid/60124
- http://www.ubuntu.com/usn/USN-1859-1
- http://www.x.org/wiki/Development/Security/Advisory-2013-05-23