CVE-2013-1986: Buffer Overflow
Published Jun 15, 2013
·Updated
Multiple integer overflows in X.org libXrandr 1.4.0 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRRQueryOutputProperty and (2) XRRQueryProviderProperty functions.
Affected Software
9 affected components
X libXrandr<=1.4.0
X libXrandr=1.2.3
X libXrandr=1.2.99.1
X libXrandr=1.2.99.2
X libXrandr=1.2.99.3
X libXrandr=1.2.99.4
X libXrandr=1.3.0
X libXrandr=1.3.1
X libXrandr=1.3.2
Event History
Jun 15, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1986?
CVE-2013-1986 has a moderate severity level due to risks of memory corruption and potential system crashes.
2
How do I fix CVE-2013-1986?
To fix CVE-2013-1986, upgrade to libXrandr version 1.4.1 or later.
3
What are the consequences of exploiting CVE-2013-1986?
Exploiting CVE-2013-1986 can lead to unexpected behavior, including buffer overflows that may crash the X server.
4
What versions of libXrandr are affected by CVE-2013-1986?
CVE-2013-1986 affects libXrandr versions 1.4.0 and earlier.
5
What functions are related to the vulnerability in CVE-2013-1986?
The vulnerability in CVE-2013-1986 is related to the XRRQueryOutputProperty and XRRQueryProviderProperty functions.