Openchrome X Window System Client Libraries CVE-2013-1994 Multiple Integer Overflow Vulnerabilities
BID:60151
Info
Openchrome X Window System Client Libraries CVE-2013-1994 Multiple Integer Overflow Vulnerabilities
| Bugtraq ID: | 60151 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-1994 |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2013 12:00AM |
| Updated: | Apr 13 2015 10:17PM |
| Credit: | Ilja van Sprundel of IOActive |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.04 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS Openchrome Openchrome 0.3.2 Gentoo Linux Debian Linux 7.0 |
| Not Vulnerable: | |
Discussion
Openchrome X Window System Client Libraries CVE-2013-1994 Multiple Integer Overflow Vulnerabilities
Openchrome is prone to multiple integer-overflow vulnerabilities because it fails to properly validate user-supplied input.
Successful exploits may allow the attacker to execute arbitrary code in the context of applications that use the affected library. Failed exploit attempts will likely result in denial-of-service conditions.
openChrome 0.3.2 and earlier are vulnerable.
Openchrome is prone to multiple integer-overflow vulnerabilities because it fails to properly validate user-supplied input.
Successful exploits may allow the attacker to execute arbitrary code in the context of applications that use the affected library. Failed exploit attempts will likely result in denial-of-service conditions.
openChrome 0.3.2 and earlier are vulnerable.
Exploit / POC
Openchrome X Window System Client Libraries CVE-2013-1994 Multiple Integer Overflow Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Openchrome X Window System Client Libraries CVE-2013-1994 Multiple Integer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Openchrome X Window System Client Libraries CVE-2013-1994 Multiple Integer Overflow Vulnerabilities
References:
References:
- [ANNOUNCE] X.Org Security Advisory: Protocol handling issues in X Window System (seclists)
- [SECURITY] [DSA 2679-1] xserver-xorg-video-openchrome security update (seclists)
- Openchrome Homepage (Openchrome)
- Protocol handling issues in X Window System client libraries (X.Org)
- USN-1871-1: xserver-xorg-video-openchrome vulnerability (Ubuntu)