CVE-2013-2005

NONE EPSS 79.3%
Published Jun 15, 201313y ago · Modified Jun 16, 20262w ago
Find Similar
Published Jun 15, 2013 13y ago
Last Modified Jun 16, 2026 2w ago

Description

X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.

Threat Intelligence

EPSS Exploit Probability
79.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety

Affected Products 10

VendorProductVersionRange
xlibxt* ≤1.1.3
xlibxt1.0.3any
xlibxt1.0.4any
xlibxt1.0.5any
xlibxt1.0.6any
xlibxt1.0.7any
xlibxt1.0.8any
xlibxt1.0.9any
xlibxt1.1.1any
xlibxt1.1.2any

References 7

  • lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106785.html
  • lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2013-06/msg00138.html
  • debian.org http://www.debian.org/security/2013/dsa-2680
  • openwall.com http://www.openwall.com/lists/oss-security/2013/05/23/3
  • securityfocus.com http://www.securityfocus.com/bid/60133
  • ubuntu.com http://www.ubuntu.com/usn/USN-1865-1
  • x.org http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.