PublicDateAtUSN: 2013-05-23 15:00:00 UTC Candidate: CVE-2013-1995 CRD: 2013-05-23 15:00:00 UTC PublicDate: 2013-06-15 20:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1995 http://www.x.org/wiki/Development/Security/Advisory-2013-05-23 http://www.debian.org/security/2013/dsa-2683 https://ubuntu.com/security/notices/USN-1859-1 Description: X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Ilja van Sprundel Assigned-to: mdeslaur CVSS: Patches_libxi: upstream: http://cgit.freedesktop.org/xorg/lib/libXi/commit/?id=81b4df8ac6aa1520c41c3526961014a6f115cc46 (1/1) upstream_libxi: pending (1.7.2) lucid_libxi: released (2:1.3-3ubuntu0.2) precise_libxi: released (2:1.6.0-0ubuntu2.1) quantal_libxi: released (2:1.6.1-1ubuntu0.1) raring_libxi: released (2:1.6.99.1-0ubuntu3.1) devel_libxi: released (2:1.6.99.1-0ubuntu4)