First published: Thu Apr 16 2015(Updated: )
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE LibX11-6 (32-bit) | =1.0.1 | |
SUSE LibX11-6 (32-bit) | =1.0.2 | |
SUSE LibX11-6 (32-bit) | =1.0.3 | |
SUSE LibX11-6 (32-bit) | =1.1 | |
SUSE LibX11-6 (32-bit) | =1.1-rc1 | |
SUSE LibX11-6 (32-bit) | =1.1-rc2 | |
SUSE LibX11-6 (32-bit) | =1.1.4 | |
SUSE LibX11-6 (32-bit) | =1.1.5 | |
SUSE LibX11-6 (32-bit) | =1.1.6 | |
SUSE LibX11-6 (32-bit) | =1.1.99.1 | |
SUSE LibX11-6 (32-bit) | =1.1.99.2 | |
SUSE LibX11-6 (32-bit) | =1.2 | |
SUSE LibX11-6 (32-bit) | =1.2.1 | |
SUSE LibX11-6 (32-bit) | =1.2.2 | |
SUSE LibX11-6 (32-bit) | =1.3 | |
SUSE LibX11-6 (32-bit) | =1.3.1 | |
SUSE LibX11-6 (32-bit) | =1.3.2 | |
SUSE LibX11-6 (32-bit) | =1.3.3 | |
SUSE LibX11-6 (32-bit) | =1.3.4 | |
SUSE LibX11-6 (32-bit) | =1.3.5 | |
SUSE LibX11-6 (32-bit) | =1.3.6 | |
SUSE LibX11-6 (32-bit) | =1.3.99.901 | |
SUSE LibX11-6 (32-bit) | =1.3.99.902 | |
SUSE LibX11-6 (32-bit) | =1.3.99.903 | |
SUSE LibX11-6 (32-bit) | =1.4.0 | |
SUSE LibX11-6 (32-bit) | =1.4.1 | |
SUSE LibX11-6 (32-bit) | =1.4.2 | |
SUSE LibX11-6 (32-bit) | =1.4.3 | |
SUSE LibX11-6 (32-bit) | =1.4.4 | |
SUSE LibX11-6 (32-bit) | =1.4.99.901 | |
SUSE LibX11-6 (32-bit) | =1.4.99.902 | |
SUSE LibX11-6 (32-bit) | =1.5.0 | |
SUSE LibX11-6 (32-bit) | =1.5.99.901 | |
SUSE LibX11-6 (32-bit) | =1.5.99.902 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Debian | =7.0 | |
Oracle Xorg-x11-drv-void | =6.0 | |
Oracle Xorg-x11-drv-void | =6.1 | |
Oracle Xorg-x11-drv-void | =6.3 | |
Oracle Xorg-x11-drv-void | =6.4 | |
Oracle Xorg-x11-drv-void | =6.5.1 | |
Oracle Xorg-x11-drv-void | =6.6 | |
Oracle Xorg-x11-drv-void | =6.7 | |
Oracle Xorg-x11-drv-void | =6.8.0 | |
Oracle Xorg-x11-drv-void | =6.8.1 | |
Oracle Xorg-x11-drv-void | =6.8.2 | |
Oracle Xorg-x11-drv-void | =6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7439 is considered to have a high severity due to its potential to cause buffer overflow vulnerabilities.
To mitigate CVE-2013-7439, update libX11 to version 1.6.0 or later, or apply available patches for the affected versions.
CVE-2013-7439 affects libX11 versions prior to 1.6.0, including specific versions like 1.0.1 to 1.5.99.902.
Yes, CVE-2013-7439 can be exploited remotely by sending crafted requests to the vulnerable application.
Applications that rely on X.Org's libX11 for graphical user interface functionality may be affected by CVE-2013-7439.