Buffer overflow in libXxf86dga - CVE-2013-2000
Published: June 15, 2013 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Multiple buffer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XDGAQueryModes and (2) XDGASetMode functions.
Affected software
Amazon Linux AMI
libxxf86dga (Alpine package)
How to mitigate CVE-2013-2000
libxxf86dga (Alpine package) - addressed in versions 1.1.3-r1, 1.1.3-r2