Lucene search

K
cve[email protected]CVE-2013-1994
HistoryJun 15, 2013 - 7:55 p.m.

CVE-2013-1994

2013-06-1519:55:01
CWE-189
web.nvd.nist.gov
40
cve-2013-1994
x.org
libchromexvmc
libchromexvmcpro
openchrome
buffer overflow
integer overflow
memory allocation
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.8%

Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.

Affected configurations

NVD
Node
openchromeopenchromeRange0.3.2
OR
xlibchromexvmcMatch-
OR
xlibchromexvmcproMatch-

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.8%