Buffer overflow in libx11 - CVE-2013-2004
Published: June 15, 2013 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.
Affected software
HP-UX
Amazon Linux AMI
libx11 (Alpine package)
IBM BladeCenter Advanced Management Module
How to mitigate CVE-2013-2004
libx11 (Alpine package) - update to 1.4.4-r1
IBM BladeCenter Advanced Management Module - update to BPET68C-3.68C
External References
Related Security Bulletins
- Buffer overflow in xorg.freedesktop libx11
- Buffer overflow in libx11 (Alpine package)
- Amazon Linux AMI update for libX11, libXcursor, libXfixes, libXi, libXrandr, libXrender, libXres, libXt, libXv, libXvMC, libXxf86dga, libXxf86vm, libdmx, xorg-x11-proto-devel
- Multiple vulnerabilities in HP-UX Running X Windows Libraries
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module (AMM)