CVE-2013-2001: Buffer Overflow
Published Jun 15, 2013
·Updated
Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XF86VidModeGetGammaRamp function.
Affected Software
6 affected components
X libXxf86vm<=1.1.2
X libXxf86vm=1.0.1
X libXxf86vm=1.0.2
X libXxf86vm=1.0.99.1
X libXxf86vm=1.1.0
X libXxf86vm=1.1.1
Event History
Jun 15, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2001?
CVE-2013-2001 is classified as a high severity vulnerability due to the potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2013-2001?
To fix CVE-2013-2001, upgrade to the patched version of libXxf86vm that is later than 1.1.2.
3
What impact does CVE-2013-2001 have on affected systems?
CVE-2013-2001 can lead to crashes of the X server and may allow attackers to execute arbitrary code.
4
Which versions of libXxf86vm are affected by CVE-2013-2001?
Versions of libXxf86vm up to and including 1.1.2 are affected by CVE-2013-2001.
5
Is CVE-2013-2001 exploitable remotely?
CVE-2013-2001 can potentially be exploited remotely depending on the configuration of the X server.