CVE-2013-1998: Buffer Overflow
Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1998?
CVE-2013-1998 is classified as a high severity vulnerability due to its potential for denial of service and arbitrary code execution.
How do I fix CVE-2013-1998?
To fix CVE-2013-1998, upgrade to libXi version 1.7.2 or later, which includes security patches for this vulnerability.
Which versions of X.org libXi are affected by CVE-2013-1998?
CVE-2013-1998 affects all versions of X.org libXi up to and including version 1.7.1.
What are the potential impacts of exploiting CVE-2013-1998?
Exploiting CVE-2013-1998 can lead to a crash of the X server and may allow attackers to execute arbitrary code.
What functions are associated with CVE-2013-1998?
The functions associated with CVE-2013-1998 are XGetDeviceButtonMapping, XIPassiveGrabDevice, and XQueryDeviceState.