Input validation error in libx11 - CVE-2013-1981
Published: June 15, 2013 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeyboardMapping, (9) XGetWindowProperty, (10) XGetImage, (11) LoadColornameDB, (12) XrmGetFileDatabase, (13) _XimParseStringFile, or (14) TransFileName functions. Additional products added per http://www.ubuntu.com/usn/USN-1854-1/
Affected software
HP-UX
Amazon Linux AMI
libx11 (Alpine package)
IBM BladeCenter Advanced Management Module
How to mitigate CVE-2013-1981
libx11 (Alpine package) - update to 1.4.4-r1
IBM BladeCenter Advanced Management Module - update to BPET68C-3.68C
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106781.html
- http://www.debian.org/security/2013/dsa-2693
- http://www.openwall.com/lists/oss-security/2013/05/23/3
- http://www.securityfocus.com/bid/60120
- http://www.ubuntu.com/usn/USN-1854-1
- http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
Related Security Bulletins
- Input validation error in xorg.freedesktop libx11
- Input validation error in libx11 (Alpine package)
- Amazon Linux AMI update for libX11, libXcursor, libXfixes, libXi, libXrandr, libXrender, libXres, libXt, libXv, libXvMC, libXxf86dga, libXxf86vm, libdmx, xorg-x11-proto-devel
- Multiple vulnerabilities in HP-UX Running X Windows Libraries
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module (AMM)