ubuntu · CVE-2013-2005

Quick triage

Priority: medium 公開: 2013-05-23 15:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

参照: Official ubuntu advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2013-2005 medium priority: Ubuntu including 1 source packages (libxt), 5 status rows across 5 suites (lucid, precise, quantal, raring, upstream): released 4, pending 1.

Description:

X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.

cvelogic Threat Intelligence