CVE-2013-1984: Buffer Overflow
Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (5) XIGetProperty, (6) XIGetSelectedEvents, (7) XGetDeviceProperties, and (8) XListInputDevices functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1984?
CVE-2013-1984 is classified as a high severity vulnerability due to its potential to cause a buffer overflow and subsequent allocation of insufficient memory.
How do I fix CVE-2013-1984?
To fix CVE-2013-1984, update X.org libXi to version 1.7.2 or later, which addresses the integer overflow vulnerabilities.
What software versions are affected by CVE-2013-1984?
CVE-2013-1984 affects X.org libXi versions 1.7.1 and earlier.
What are the potential impacts of CVE-2013-1984?
The impacts of CVE-2013-1984 may include denial of service or potentially arbitrary code execution due to memory errors.
Is there any workaround for CVE-2013-1984 if I cannot update immediately?
While the best solution is to update, you may restrict access to affected components as a temporary workaround for CVE-2013-1984.