PublicDateAtUSN: 2013-05-23 15:00:00 UTC Candidate: CVE-2013-1983 CRD: 2013-05-23 15:00:00 UTC PublicDate: 2013-06-15 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1983 http://www.x.org/wiki/Development/Security/Advisory-2013-05-23 http://www.debian.org/security/2013/dsa-2676 https://ubuntu.com/security/notices/USN-1858-1 Description: Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XFixesGetCursorImage function. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Ilja van Sprundel Assigned-to: mdeslaur CVSS: Patches_libxfixes: upstream: http://cgit.freedesktop.org/xorg/lib/libXfixes/commit/?id=b031e3b60fa1af9e49449f23d4a84395868be3ab upstream: http://cgit.freedesktop.org/xorg/lib/libXfixes/commit/?id=c480fe3271873ec7471b0cbd680f4dac18ca8904 (1/1) upstream_libxfixes: pending (5.0.1) lucid_libxfixes: ignored (reached end-of-life) precise_libxfixes: released (1:5.0-4ubuntu4.1) quantal_libxfixes: released (1:5.0-4ubuntu5.12.10.1) raring_libxfixes: released (1:5.0-4ubuntu5.13.04.1) devel_libxfixes: released (1:5.0-4ubuntu6)