CVE-2013-1991: Buffer Overflow
Multiple integer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XDGAQueryModes and (2) XDGASetMode functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1991?
CVE-2013-1991 has been classified as a moderate severity vulnerability due to its potential for buffer overflow and memory allocation issues.
How do I fix CVE-2013-1991?
To fix CVE-2013-1991, update the libXxf86dga package to version 1.1.4 or later to mitigate the integer overflow issues.
Which versions of libXxf86dga are affected by CVE-2013-1991?
CVE-2013-1991 affects libXxf86dga versions 1.1.3 and earlier, including specific versions such as 1.0.1, 1.0.2, and 1.1.2.
Can CVE-2013-1991 lead to system compromise?
Yes, CVE-2013-1991 could potentially lead to system compromise through exploitation of the buffer overflow vulnerability.
What are the affected functions in CVE-2013-1991?
The affected functions in CVE-2013-1991 are XDGAQueryModes and XDGASetMode, which can trigger memory allocation failures.