CVE-2013-1997: Buffer Overflow
Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) XkbReadGetDeviceInfoReply, (3) XkbReadGeomShapes, (4) XkbReadGetGeometryReply, (5) XkbReadKeySyms, (6) XkbReadKeyActions, (7) XkbReadKeyBehaviors, (8) XkbReadModifierMap, (9) XkbReadExplicitComponents, (10) XkbReadVirtualModMap, (11) XkbReadGetNamesReply, (12) XkbReadGetMapReply, (13) XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1997?
CVE-2013-1997 has a high severity level due to its potential to cause denial of service and execute arbitrary code.
How do I fix CVE-2013-1997?
To fix CVE-2013-1997, update your libX11 package to version 1.6 or later.
What does CVE-2013-1997 affect?
CVE-2013-1997 affects X.org libX11 versions up to and including 1.5.99.901 and the exact version 1.5.0.
What are the consequences of CVE-2013-1997?
The consequences of CVE-2013-1997 include crashes of the X server and potential arbitrary code execution.
Is CVE-2013-1997 actively exploited?
There have been no public reports indicating active exploitation of CVE-2013-1997, but it remains a risk due to its severity.