CVE-2013-1997

Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4) _XkbReadGetGeometryReply, (5) _XkbReadKeySyms, (6) _XkbReadKeyActions, (7) _XkbReadKeyBehaviors, (8) _XkbReadModifierMap, (9) _XkbReadExplicitComponents, (10) _XkbReadVirtualModMap, (11) _XkbReadGetNamesReply, (12) _XkbReadGetMapReply, (13) _XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
xlibx11
𝑥
≤ 1.5.99.901
xlibx11
1.5.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libx11
bookworm
2:1.8.4-2+deb12u2
fixed
bookworm (security)
2:1.8.4-2+deb12u2
fixed
bullseye
2:1.7.2-1+deb11u2
fixed
bullseye (security)
2:1.7.2-1+deb11u2
fixed
sid
2:1.8.10-1
fixed
trixie
2:1.8.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libx11
lucid
Fixed 2:1.3.2-1ubuntu3.1
released
precise
Fixed 2:1.4.99.1-0ubuntu2.1
released
quantal
Fixed 2:1.5.0-1ubuntu0.1
released
raring
Fixed 2:1.5.0-1ubuntu1.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libX11-6
suse enterprise desktop 15
1.6.5-1.41
fixed
suse enterprise desktop 15 SP1
1.6.5-3.3.1
fixed
suse enterprise desktop 15 SP2
1.6.5-3.3.1
fixed
suse enterprise sap 12 SP5
1.6.2-12.5.1
fixed
suse enterprise sap 15
1.6.5-1.41
fixed
suse enterprise sap 15 SP1
1.6.5-3.3.1
fixed
suse enterprise sap 15 SP2
1.6.5-3.3.1
fixed
suse enterprise server 12
1.6.2-4.12
fixed
suse enterprise server 12 SP1
1.6.2-4.12
fixed
suse enterprise server 12 SP2
1.6.2-4.12
fixed
suse enterprise server 12 SP4
1.6.2-12.5.1
fixed
suse enterprise server 12 SP5
1.6.2-12.5.1
fixed
suse enterprise server 15
1.6.5-1.41
fixed
suse enterprise server 15 SP1
1.6.5-3.3.1
fixed
suse enterprise server 15 SP2
1.6.5-3.3.1
fixed
libX11-6-32bit
suse enterprise desktop 15
1.6.5-1.41
fixed
suse enterprise desktop 15 SP1
1.6.5-3.3.1
fixed
suse enterprise desktop 15 SP2
1.6.5-3.3.1
fixed
suse enterprise sap 12 SP5
1.6.2-12.5.1
fixed
suse enterprise sap 15
1.6.5-1.41
fixed
suse enterprise sap 15 SP1
1.6.5-3.3.1
fixed
suse enterprise sap 15 SP2
1.6.5-3.3.1
fixed
suse enterprise server 12
1.6.2-4.12
fixed
suse enterprise server 12 SP1
1.6.2-4.12
fixed
suse enterprise server 12 SP2
1.6.2-4.12
fixed
suse enterprise server 12 SP4
1.6.2-12.5.1
fixed
suse enterprise server 12 SP5
1.6.2-12.5.1
fixed
suse enterprise server 15
1.6.5-1.41
fixed
suse enterprise server 15 SP1
1.6.5-3.3.1
fixed
suse enterprise server 15 SP2
1.6.5-3.3.1
fixed
libX11-data
suse enterprise desktop 15
1.6.5-1.41
fixed
suse enterprise desktop 15 SP1
1.6.5-3.3.1
fixed
suse enterprise desktop 15 SP2
1.6.5-3.3.1
fixed
suse enterprise sap 12 SP5
1.6.2-12.5.1
fixed
suse enterprise sap 15
1.6.5-1.41
fixed
suse enterprise sap 15 SP1
1.6.5-3.3.1
fixed
suse enterprise sap 15 SP2
1.6.5-3.3.1
fixed
suse enterprise server 12
1.6.2-4.12
fixed
suse enterprise server 12 SP1
1.6.2-4.12
fixed
suse enterprise server 12 SP2
1.6.2-4.12
fixed
suse enterprise server 12 SP4
1.6.2-12.5.1
fixed
suse enterprise server 12 SP5
1.6.2-12.5.1
fixed
suse enterprise server 15
1.6.5-1.41
fixed
suse enterprise server 15 SP1
1.6.5-3.3.1
fixed
suse enterprise server 15 SP2
1.6.5-3.3.1
fixed
libX11-devel
suse enterprise desktop 15
1.6.5-1.41
fixed
suse enterprise desktop 15 SP1
1.6.5-3.3.1
fixed
suse enterprise desktop 15 SP2
1.6.5-3.3.1
fixed
suse enterprise sap 15
1.6.5-1.41
fixed
suse enterprise sap 15 SP1
1.6.5-3.3.1
fixed
suse enterprise sap 15 SP2
1.6.5-3.3.1
fixed
suse enterprise server 15
1.6.5-1.41
fixed
suse enterprise server 15 SP1
1.6.5-3.3.1
fixed
suse enterprise server 15 SP2
1.6.5-3.3.1
fixed
libX11-xcb1
suse enterprise desktop 15
1.6.5-1.41
fixed
suse enterprise desktop 15 SP1
1.6.5-3.3.1
fixed
suse enterprise desktop 15 SP2
1.6.5-3.3.1
fixed
suse enterprise sap 12 SP5
1.6.2-12.5.1
fixed
suse enterprise sap 15
1.6.5-1.41
fixed
suse enterprise sap 15 SP1
1.6.5-3.3.1
fixed
suse enterprise sap 15 SP2
1.6.5-3.3.1
fixed
suse enterprise server 12
1.6.2-4.12
fixed
suse enterprise server 12 SP1
1.6.2-4.12
fixed
suse enterprise server 12 SP2
1.6.2-4.12
fixed
suse enterprise server 12 SP4
1.6.2-12.5.1
fixed
suse enterprise server 12 SP5
1.6.2-12.5.1
fixed
suse enterprise server 15
1.6.5-1.41
fixed
suse enterprise server 15 SP1
1.6.5-3.3.1
fixed
suse enterprise server 15 SP2
1.6.5-3.3.1
fixed
libX11-xcb1-32bit
suse enterprise desktop 15
1.6.5-1.41
fixed
suse enterprise desktop 15 SP1
1.6.5-3.3.1
fixed
suse enterprise desktop 15 SP2
1.6.5-3.3.1
fixed
suse enterprise sap 12 SP5
1.6.2-12.5.1
fixed
suse enterprise sap 15
1.6.5-1.41
fixed
suse enterprise sap 15 SP1
1.6.5-3.3.1
fixed
suse enterprise sap 15 SP2
1.6.5-3.3.1
fixed
suse enterprise server 12
1.6.2-4.12
fixed
suse enterprise server 12 SP1
1.6.2-4.12
fixed
suse enterprise server 12 SP2
1.6.2-4.12
fixed
suse enterprise server 12 SP4
1.6.2-12.5.1
fixed
suse enterprise server 12 SP5
1.6.2-12.5.1
fixed
suse enterprise server 15
1.6.5-1.41
fixed
suse enterprise server 15 SP1
1.6.5-3.3.1
fixed
suse enterprise server 15 SP2
1.6.5-3.3.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libX11
RHEL 6
0:1.6.0-2.2.el6
fixed
libX11-common
RHEL 6
0:1.6.0-2.2.el6
fixed
libX11-devel
RHEL 6
0:1.6.0-2.2.el6
fixed
libXcursor
RHEL 6
0:1.1.14-2.1.el6
fixed
libXcursor-devel
RHEL 6
0:1.1.14-2.1.el6
fixed
libXext
RHEL 6
0:1.3.2-2.1.el6
fixed
libXext-devel
RHEL 6
0:1.3.2-2.1.el6
fixed
libXfixes
RHEL 6
0:5.0.1-2.1.el6
fixed
libXfixes-devel
RHEL 6
0:5.0.1-2.1.el6
fixed
libXi
RHEL 6
0:1.7.2-2.2.el6
fixed
libXi-devel
RHEL 6
0:1.7.2-2.2.el6
fixed
libXinerama
RHEL 6
0:1.1.3-2.1.el6
fixed
libXinerama-devel
RHEL 6
0:1.1.3-2.1.el6
fixed
libXp
RHEL 6
0:1.0.2-2.1.el6
fixed
libXp-devel
RHEL 6
0:1.0.2-2.1.el6
fixed
libXrandr
RHEL 6
0:1.4.1-2.1.el6
fixed
libXrandr-devel
RHEL 6
0:1.4.1-2.1.el6
fixed
libXrender
RHEL 6
0:0.9.8-2.1.el6
fixed
libXrender-devel
RHEL 6
0:0.9.8-2.1.el6
fixed
libXres
RHEL 6
0:1.0.7-2.1.el6
fixed
libXres-devel
RHEL 6
0:1.0.7-2.1.el6
fixed
libXt
RHEL 6
0:1.1.4-6.1.el6
fixed
libXt-devel
RHEL 6
0:1.1.4-6.1.el6
fixed
libXtst
RHEL 6
0:1.2.2-2.1.el6
fixed
libXtst-devel
RHEL 6
0:1.2.2-2.1.el6
fixed
libXv
RHEL 6
0:1.0.9-2.1.el6
fixed
libXv-devel
RHEL 6
0:1.0.9-2.1.el6
fixed
libXvMC
RHEL 6
0:1.0.8-2.1.el6
fixed
libXvMC-devel
RHEL 6
0:1.0.8-2.1.el6
fixed
libXxf86dga
RHEL 6
0:1.1.4-2.1.el6
fixed
libXxf86dga-devel
RHEL 6
0:1.1.4-2.1.el6
fixed
libXxf86vm
RHEL 6
0:1.1.3-2.1.el6
fixed
libXxf86vm-devel
RHEL 6
0:1.1.3-2.1.el6
fixed
libdmx
RHEL 6
0:1.1.3-3.el6
fixed
libdmx-devel
RHEL 6
0:1.1.3-3.el6
fixed
libxcb
RHEL 6
0:1.9.1-2.el6
fixed
libxcb-devel
RHEL 6
0:1.9.1-2.el6
fixed
libxcb-doc
RHEL 6
0:1.9.1-2.el6
fixed
libxcb-python
RHEL 6
0:1.9.1-2.el6
fixed
xcb-proto
RHEL 6
0:1.8-3.el6
fixed
xkeyboard-config
RHEL 6
0:2.11-1.el6
fixed
xkeyboard-config-devel
RHEL 6
0:2.11-1.el6
fixed
xorg-x11-proto-devel
RHEL 6
0:7.7-9.el6
fixed
xorg-x11-xtrans-devel
RHEL 6
0:1.3.4-1.el6
fixed