Lucene search

K
cveRedhatCVE-2013-1998
HistoryJun 15, 2013 - 8:55 p.m.

CVE-2013-1998

2013-06-1520:55:00
CWE-119
redhat
web.nvd.nist.gov
55
cve
2013
1998
buffer overflow
x.org
libxi
denial of service
crash
arbitrary code
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

9.4

Confidence

High

EPSS

0.011

Percentile

84.7%

Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.

Affected configurations

Nvd
Node
x.orglibxiRange1.7.1
OR
x.orglibxiMatch1.5.0
OR
x.orglibxiMatch1.5.99.2
OR
x.orglibxiMatch1.5.99.3
OR
x.orglibxiMatch1.6.0
OR
x.orglibxiMatch1.6.1
OR
x.orglibxiMatch1.6.2
OR
x.orglibxiMatch1.6.99.1
OR
x.orglibxiMatch1.7
VendorProductVersionCPE
x.orglibxi*cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
x.orglibxi1.5.0cpe:2.3:a:x.org:libxi:1.5.0:*:*:*:*:*:*:*
x.orglibxi1.5.99.2cpe:2.3:a:x.org:libxi:1.5.99.2:*:*:*:*:*:*:*
x.orglibxi1.5.99.3cpe:2.3:a:x.org:libxi:1.5.99.3:*:*:*:*:*:*:*
x.orglibxi1.6.0cpe:2.3:a:x.org:libxi:1.6.0:*:*:*:*:*:*:*
x.orglibxi1.6.1cpe:2.3:a:x.org:libxi:1.6.1:*:*:*:*:*:*:*
x.orglibxi1.6.2cpe:2.3:a:x.org:libxi:1.6.2:*:*:*:*:*:*:*
x.orglibxi1.6.99.1cpe:2.3:a:x.org:libxi:1.6.99.1:*:*:*:*:*:*:*
x.orglibxi1.7cpe:2.3:a:x.org:libxi:1.7:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

9.4

Confidence

High

EPSS

0.011

Percentile

84.7%