CVE-2013-1987

Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
canonicalubuntu_linux
10.04
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
opensuseopensuse
12.2
opensuseopensuse
12.3
xlibxrender
𝑥
≤ 0.9.7
xlibxrender
0.9.1
xlibxrender
0.9.2
xlibxrender
0.9.3
xlibxrender
0.9.4
xlibxrender
0.9.5
xlibxrender
0.9.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxrender
bookworm
1:0.9.10-1.1
fixed
bullseye
1:0.9.10-1
fixed
sid
1:0.9.10-1.1
fixed
trixie
1:0.9.10-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxrender
lucid
Fixed 1:0.9.5-1ubuntu0.1
released
precise
Fixed 1:0.9.6-2ubuntu0.1
released
quantal
Fixed 1:0.9.7-1ubuntu0.12.10.1
released
raring
Fixed 1:0.9.7-1ubuntu0.13.04.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libXrender1
suse enterprise sap 12 SP5
0.9.8-7.1
fixed
suse enterprise server 12
0.9.8-3.56
fixed
suse enterprise server 12 SP1
0.9.8-3.56
fixed
suse enterprise server 12 SP2
0.9.8-3.56
fixed
suse enterprise server 12 SP3
0.9.8-7.1
fixed
suse enterprise server 12 SP4
0.9.8-7.1
fixed
suse enterprise server 12 SP5
0.9.8-7.1
fixed
libXrender1-32bit
suse enterprise sap 12 SP5
0.9.8-7.1
fixed
suse enterprise server 12
0.9.8-3.56
fixed
suse enterprise server 12 SP1
0.9.8-3.56
fixed
suse enterprise server 12 SP2
0.9.8-3.56
fixed
suse enterprise server 12 SP3
0.9.8-7.1
fixed
suse enterprise server 12 SP4
0.9.8-7.1
fixed
suse enterprise server 12 SP5
0.9.8-7.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libX11
RHEL 6
0:1.6.0-2.2.el6
fixed
libX11-common
RHEL 6
0:1.6.0-2.2.el6
fixed
libX11-devel
RHEL 6
0:1.6.0-2.2.el6
fixed
libXcursor
RHEL 6
0:1.1.14-2.1.el6
fixed
libXcursor-devel
RHEL 6
0:1.1.14-2.1.el6
fixed
libXext
RHEL 6
0:1.3.2-2.1.el6
fixed
libXext-devel
RHEL 6
0:1.3.2-2.1.el6
fixed
libXfixes
RHEL 6
0:5.0.1-2.1.el6
fixed
libXfixes-devel
RHEL 6
0:5.0.1-2.1.el6
fixed
libXi
RHEL 6
0:1.7.2-2.2.el6
fixed
libXi-devel
RHEL 6
0:1.7.2-2.2.el6
fixed
libXinerama
RHEL 6
0:1.1.3-2.1.el6
fixed
libXinerama-devel
RHEL 6
0:1.1.3-2.1.el6
fixed
libXp
RHEL 6
0:1.0.2-2.1.el6
fixed
libXp-devel
RHEL 6
0:1.0.2-2.1.el6
fixed
libXrandr
RHEL 6
0:1.4.1-2.1.el6
fixed
libXrandr-devel
RHEL 6
0:1.4.1-2.1.el6
fixed
libXrender
RHEL 6
0:0.9.8-2.1.el6
fixed
libXrender-devel
RHEL 6
0:0.9.8-2.1.el6
fixed
libXres
RHEL 6
0:1.0.7-2.1.el6
fixed
libXres-devel
RHEL 6
0:1.0.7-2.1.el6
fixed
libXt
RHEL 6
0:1.1.4-6.1.el6
fixed
libXt-devel
RHEL 6
0:1.1.4-6.1.el6
fixed
libXtst
RHEL 6
0:1.2.2-2.1.el6
fixed
libXtst-devel
RHEL 6
0:1.2.2-2.1.el6
fixed
libXv
RHEL 6
0:1.0.9-2.1.el6
fixed
libXv-devel
RHEL 6
0:1.0.9-2.1.el6
fixed
libXvMC
RHEL 6
0:1.0.8-2.1.el6
fixed
libXvMC-devel
RHEL 6
0:1.0.8-2.1.el6
fixed
libXxf86dga
RHEL 6
0:1.1.4-2.1.el6
fixed
libXxf86dga-devel
RHEL 6
0:1.1.4-2.1.el6
fixed
libXxf86vm
RHEL 6
0:1.1.3-2.1.el6
fixed
libXxf86vm-devel
RHEL 6
0:1.1.3-2.1.el6
fixed
libdmx
RHEL 6
0:1.1.3-3.el6
fixed
libdmx-devel
RHEL 6
0:1.1.3-3.el6
fixed
libxcb
RHEL 6
0:1.9.1-2.el6
fixed
libxcb-devel
RHEL 6
0:1.9.1-2.el6
fixed
libxcb-doc
RHEL 6
0:1.9.1-2.el6
fixed
libxcb-python
RHEL 6
0:1.9.1-2.el6
fixed
xcb-proto
RHEL 6
0:1.8-3.el6
fixed
xkeyboard-config
RHEL 6
0:2.11-1.el6
fixed
xkeyboard-config-devel
RHEL 6
0:2.11-1.el6
fixed
xorg-x11-proto-devel
RHEL 6
0:7.7-9.el6
fixed
xorg-x11-xtrans-devel
RHEL 6
0:1.3.4-1.el6
fixed
Common Weakness Enumeration