[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-452 ---- libX11 libXcursor libXfixes libXi libXrandr libXrender libXres libXt libXv libXvMC libXxf86dga libXxf86vm libdmx xorg-x11-proto-devel

ID: oval:org.secpod.oval:def:1600008Date: (C)2016-01-19   (M)2022-10-10
Class: PATCHFamily: unix




Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in the way various X11 client libraries handled certain protocol data. An attacker able to submit invalid protocol data to an X11 server via a malicious X11 client could use either of these flaws to potentially escalate their privileges on the system. Multiple array index errors, leading to heap-based buffer out-of-bounds write flaws, were found in the way various X11 client libraries handled data returned from an X11 server. A malicious X11 server could possibly use this flaw to execute arbitrary code with the privileges of the user running an X11 client. A buffer overflow flaw was found in the way the XListInputDevices function of X.Org X11"s libXi runtime library handled signed numbers. A malicious X11 server could possibly use this flaw to execute arbitrary code with the privileges of the user running an X11 client. A flaw was found in the way the X.Org X11 libXt runtime library used uninitialized pointers. A malicious X11 server could possibly use this flaw to execute arbitrary code with the privileges of the user running an X11 client. Two stack-based buffer overflow flaws were found in the way libX11, the Core X11 protocol client library, processed certain user-specified files. A malicious X11 server could possibly use this flaw to crash an X11 client via a specially crafted file

Platform:
Amazon Linux AMI
Product:
libX11
libXcursor
libXfixes
libXi
libXrandr
libXrender
libXres
libXt
libXv
libXvMC
libXxf86dga
libXxf86vm
libdmx
xorg-x11-proto-devel
Reference:
ALAS-2014-452
CVE-2013-2062
CVE-2013-2064
CVE-2013-2066
CVE-2013-2003
CVE-2013-2002
CVE-2013-2001
CVE-2013-2000
CVE-2013-2005
CVE-2013-2004
CVE-2013-1990
CVE-2013-1991
CVE-2013-1995
CVE-2013-1998
CVE-2013-1999
CVE-2013-1989
CVE-2013-1988
CVE-2013-1987
CVE-2013-1986
CVE-2013-1985
CVE-2013-1984
CVE-2013-1983
CVE-2013-1982
CVE-2013-1981
CVE-2013-1997
CVE    24
CVE-2013-2005
CVE-2013-2004
CVE-2013-2001
CVE-2013-2000
...
CPE    92
cpe:/a:x:libx11:1.5.99.901
cpe:/a:x:libxrandr:1.3.1
cpe:/a:x:libxrandr:1.3.0
cpe:/a:x:libxt
...

© SecPod Technologies