PublicDateAtUSN: 2013-05-23 15:00:00 UTC Candidate: CVE-2013-1982 CRD: 2013-05-23 15:00:00 UTC PublicDate: 2013-06-15 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1982 http://www.x.org/wiki/Development/Security/Advisory-2013-05-23 http://www.debian.org/security/2013/dsa-2682 https://ubuntu.com/security/notices/USN-1857-1 Description: Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XcupGetReservedColormapEntries, (2) XcupStoreColors, (3) XdbeGetVisualInfo, (4) XeviGetVisualInfo, (5) XShapeGetRectangles, and (6) XSyncListSystemCounters functions. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Ilja van Sprundel Assigned-to: mdeslaur CVSS: Patches_libxext: upstream: http://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=ca84a813716f9de691dc3f60390d83af4b5ae534 upstream: http://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=d05f27a6f74cb419ad5a437f2e4690b17e7faee5 (1/6) upstream: http://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=082d70b19848059ba78c9d1c315114fb07e8c0ef (2/6) upstream: http://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=96d1da55a08c4cd52b763cb07bdce5cdcbec4da8 (3/6) upstream: http://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=67ecdcf7e29de9fa78b421122620525ed2c7db88 (4/6) upstream: http://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=6ecd96e8be3c33e2ffad6631cea4aa0a030d93c2 (5/6) upstream: http://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=dfe6e1f3b8ede3d0bab7a5fa57f73513a09ec649 (6/6) upstream_libxext: pending (1.3.2) lucid_libxext: released (2:1.1.1-2ubuntu0.1) precise_libxext: released (2:1.3.0-3ubuntu0.1) quantal_libxext: released (2:1.3.1-2ubuntu0.12.10.1) raring_libxext: released (2:1.3.1-2ubuntu0.13.04.1) devel_libxext: not-affected (2:1.3.1-2+deb7u1)