6.8
CVSSv2

CVE-2013-2005

Published: 15/06/2013 Updated: 21/04/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

X.org libXt 1.1.3 and previous versions does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.

Vulnerable Product Search on Vulmon Subscribe to Product

x libxt 1.0.7

x libxt 1.1.1

x libxt 1.0.9

x libxt 1.0.4

x libxt 1.0.3

x libxt 1.0.6

x libxt

x libxt 1.0.8

x libxt 1.0.5

x libxt 1.1.2

Vendor Advisories

Several security issues were fixed in libxt ...
Ilja van Sprundel of IOActive discovered several security issues in multiple components of the Xorg graphics stack and the related libraries: Various integer overflows, sign handling errors in integer conversions, buffer overflows, memory corruption and missing input sanitising may lead to privilege escalation or denial of service For the oldstab ...
Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in the way various X11 client libraries handled certain protocol data An attacker able to submit invalid protocol data to an X11 server via a malicious X11 client could use either of these flaws to potentially escalate their privileges on the system (CVE-2013-1981 ...
A flaw was found in the way the XOrg X11 libXt runtime library used uninitialized pointers A malicious X11 server could possibly use this flaw to execute arbitrary code with the privileges of the user running an X11 client ...