Buffer overflow in libx11 - CVE-2013-1997
Published: June 15, 2013 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4) _XkbReadGetGeometryReply, (5) _XkbReadKeySyms, (6) _XkbReadKeyActions, (7) _XkbReadKeyBehaviors, (8) _XkbReadModifierMap, (9) _XkbReadExplicitComponents, (10) _XkbReadVirtualModMap, (11) _XkbReadGetNamesReply, (12) _XkbReadGetMapReply, (13) _XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.
Affected software
HP-UX
Amazon Linux AMI
libx11 (Alpine package)
IBM BladeCenter Advanced Management Module
How to mitigate CVE-2013-1997
libx11 (Alpine package) - update to 1.4.4-r1
IBM BladeCenter Advanced Management Module - update to 3.68G
External References
Related Security Bulletins
- Buffer overflow in xorg.freedesktop libx11
- Buffer overflow in libx11 (Alpine package)
- Amazon Linux AMI update for libX11, libXcursor, libXfixes, libXi, libXrandr, libXrender, libXres, libXt, libXv, libXvMC, libXxf86dga, libXxf86vm, libdmx, xorg-x11-proto-devel
- Multiple vulnerabilities in HP-UX Running X Windows Libraries
- Buffer overflow in IBM BladeCenter Advanced Management Module (AMM)