7.5
CVSSv2

CVE-2013-7439

Published: 16/04/2015 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 prior to 1.6.0 allow remote malicious users to have unspecified impact via a crafted request, which triggers a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

x.org libx11 1.4.99.902

x.org libx11 1.4.99.901

x.org libx11 1.3.99.901

x.org libx11 1.3.6

x.org libx11 1.2.2

x.org libx11 1.2.1

x.org libx11 1.1.99.1

x.org libx11 1.1

x.org libx11 1.4.4

x.org libx11 1.4.3

x.org libx11 1.3.5

x.org libx11 1.3.4

x.org libx11 1.2

x.org libx11 1.1.6

x.org libx11 1.0.1

x.org libx11 1.5.99.902

x.org libx11 1.4.2

x.org libx11 1.4.1

x.org libx11 1.3.3

x.org libx11 1.3.2

x.org libx11 1.1.5

x.org libx11 1.1.4

x.org libx11 1.0.2

x.org libx11 1.0.3

x.org libx11 1.5.99.901

x.org libx11 1.5.0

x.org libx11 1.4.0

x.org libx11 1.3.99.903

x.org libx11 1.3.99.902

x.org libx11 1.3.1

x.org libx11 1.3

x.org libx11 1.1.99.2

canonical ubuntu linux 14.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

debian debian linux 7.0

x.org x11 6.5.1

x.org x11 6.6

x.org x11 6.7

x.org x11 6.3

x.org x11 6.4

x.org x11 6.0

x.org x11 6.1

x.org x11 6.8.2

x.org x11 6.9

x.org x11 6.8.0

x.org x11 6.8.1

Vendor Advisories

libx11 could be made to crash or run programs if it processed specially crafted data ...
Abhishek Arya discovered a buffer overflow in the MakeBigReq macro provided by libx11, which could result in denial of service or the execution of arbitrary code Several other xorg packages (eg libxrender) will be recompiled against the fixed package after the release of this update For detailed information on the status of recompiled packages ...