CVE-2013-2002: Buffer Overflow
Published Jun 15, 2013
·Updated
Buffer overflow in X.org libXt 1.1.3 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XtResourceConfigurationEH function.
Affected Software
10 affected components
X libXt<=1.1.3
X libXt=1.0.3
X libXt=1.0.4
X libXt=1.0.5
X libXt=1.0.6
X libXt=1.0.7
X libXt=1.0.8
X libXt=1.0.9
X libXt=1.1.1
X libXt=1.1.2
Event History
Jun 15, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2002?
CVE-2013-2002 has a high severity due to the potential for denial of service and execution of arbitrary code.
2
How do I fix CVE-2013-2002?
To fix CVE-2013-2002, update the libXt package to a version later than 1.1.3.
3
Which versions of libXt are affected by CVE-2013-2002?
CVE-2013-2002 affects libXt versions 1.1.3 and earlier, including 1.0.3 to 1.0.9.
4
What type of vulnerability is CVE-2013-2002?
CVE-2013-2002 is classified as a buffer overflow vulnerability.
5
Can CVE-2013-2002 be exploited remotely?
Yes, CVE-2013-2002 can be exploited remotely if an attacker sends crafted input to the X server.