CVE-2013-2005: Buffer Overflow
X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2005?
CVE-2013-2005 has been rated as having moderate severity due to potential memory corruption issues.
How do I fix CVE-2013-2005?
To fix CVE-2013-2005, update libXt to version 1.1.4 or later.
Which versions of libXt are affected by CVE-2013-2005?
CVE-2013-2005 affects libXt versions 1.1.3 and earlier, as well as specific earlier versions down to 1.0.3.
What kind of vulnerability is CVE-2013-2005?
CVE-2013-2005 is a vulnerability that allows for memory corruption due to uninitialized pointers.
Is CVE-2013-2005 exploitable remotely?
Yes, CVE-2013-2005 can potentially be exploited remotely by triggering events in the X server.