[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-2005Date: (C)2013-06-15   (M)2023-12-22


X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-60133
DSA-2680
FEDORA-2013-9098
USN-1865-1
http://www.openwall.com/lists/oss-security/2013/05/23/3
http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
openSUSE-SU-2013:1008

CPE    10
cpe:/a:x:libxt
cpe:/a:x:libxt:1.0.8
cpe:/a:x:libxt:1.0.9
cpe:/a:x:libxt:1.0.6
...
CWE    1
CWE-119
OVAL    28
oval:org.secpod.oval:def:104973
oval:org.secpod.oval:def:1600008
oval:org.secpod.oval:def:701319
oval:org.secpod.oval:def:601020
...

© SecPod Technologies