CVE-2013-7439

EUVD-2013-7203
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
x.orglibx11
1.0.1
x.orglibx11
1.0.2
x.orglibx11
1.0.3
x.orglibx11
1.1
x.orglibx11
1.1:rc1
x.orglibx11
1.1:rc2
x.orglibx11
1.1.4
x.orglibx11
1.1.5
x.orglibx11
1.1.6
x.orglibx11
1.1.99.1
x.orglibx11
1.1.99.2
x.orglibx11
1.2
x.orglibx11
1.2.1
x.orglibx11
1.2.2
x.orglibx11
1.3
x.orglibx11
1.3.1
x.orglibx11
1.3.2
x.orglibx11
1.3.3
x.orglibx11
1.3.4
x.orglibx11
1.3.5
x.orglibx11
1.3.6
x.orglibx11
1.3.99.901
x.orglibx11
1.3.99.902
x.orglibx11
1.3.99.903
x.orglibx11
1.4.0
x.orglibx11
1.4.1
x.orglibx11
1.4.2
x.orglibx11
1.4.3
x.orglibx11
1.4.4
x.orglibx11
1.4.99.901
x.orglibx11
1.4.99.902
x.orglibx11
1.5.0
x.orglibx11
1.5.99.901
x.orglibx11
1.5.99.902
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
debiandebian_linux
7.0
x.orgx11
6.0
x.orgx11
6.1
x.orgx11
6.3
x.orgx11
6.4
x.orgx11
6.5.1
x.orgx11
6.6
x.orgx11
6.7
x.orgx11
6.8.0
x.orgx11
6.8.1
x.orgx11
6.8.2
x.orgx11
6.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libx11
bookworm
2:1.8.4-2+deb12u2
fixed
bookworm (security)
2:1.8.4-2+deb12u2
fixed
bullseye
2:1.7.2-1+deb11u2
fixed
bullseye (security)
2:1.7.2-1+deb11u2
fixed
sid
2:1.8.10-1
fixed
trixie
2:1.8.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libx11
lucid
ignored
precise
Fixed 2:1.4.99.1-0ubuntu2.3
released
trusty
not-affected
utopic
not-affected
libxrender
lucid
ignored
precise
Fixed 1:0.9.6-2ubuntu0.2
released
trusty
Fixed 1:0.9.8-1build0.14.04.1
released
utopic
Fixed 1:0.9.8-1build0.14.10.1
released
Common Weakness Enumeration