CVE-2013-2004: Buffer Overflow
Published Jun 15, 2013
·Updated
The (1) GetDatabase and (2) XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.
Affected Software
2 affected components
X libX11<=1.5.99.901
X libX11=1.5.0
Event History
Jun 15, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2004?
CVE-2013-2004 is classified as a denial of service vulnerability due to potential stack consumption.
2
How does CVE-2013-2004 affect X.org libX11?
CVE-2013-2004 allows crafted files to exploit unchecked recursion depth, causing stack overflow.
3
Which versions of X.org libX11 are affected by CVE-2013-2004?
CVE-2013-2004 affects X.org libX11 version 1.5.99.901 and earlier.
4
What can be done to mitigate CVE-2013-2004?
Mitigation for CVE-2013-2004 includes updating X.org libX11 to a version that implements recursion depth checks.
5
Is there a patch available for CVE-2013-2004?
Yes, patches have been released by various distributions to address CVE-2013-2004.