CVE-2013-1872

The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fs_visitor::remove_dead_constants function.  NOTE: this issue might be related to CVE-2013-0796.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
mesa3dmesa
9.0
mesa3dmesa
9.0.1
mesa3dmesa
9.0.2
mesa3dmesa
9.0.3
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
opensuseopensuse
12.2
opensuseopensuse
12.3
redhatenterprise_linux
6.0
mesa3dmesa
8.0
mesa3dmesa
8.0.1
mesa3dmesa
8.0.2
mesa3dmesa
8.0.3
mesa3dmesa
8.0.4
mesa3dmesa
8.0.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mesa
bullseye
20.3.5-1
fixed
squeeze
not-affected
bookworm
22.3.6-1+deb12u1
fixed
sid
24.2.4-1
fixed
trixie
24.2.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mesa
raring
Fixed 9.1.3-0ubuntu0.3
released
quantal
Fixed 9.0.3-0ubuntu0.2
released
precise
Fixed 8.0.4-0ubuntu0.6
released
lucid
ignored