PublicDateAtUSN: 2013-05-23 15:00:00 UTC Candidate: CVE-2013-2063 CRD: 2013-05-23 15:00:00 UTC PublicDate: 2013-06-15 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2063 http://www.x.org/wiki/Development/Security/Advisory-2013-05-23 http://www.debian.org/security/2013/dsa-2689 https://ubuntu.com/security/notices/USN-1866-1 Description: Integer overflow in X.org libXtst 1.2.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XRecordGetContext function. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Ilja van Sprundel Assigned-to: mdeslaur CVSS: Patches_libxtst: upstream: http://cgit.freedesktop.org/xorg/lib/libXtst/commit/?id=46ed6283034b5b7d14584009453f5d974cfacf1e upstream: http://cgit.freedesktop.org/xorg/lib/libXtst/commit/?id=e7e04b7be3f018ad636aba3a36bfc1cd80b9906d (1/1) upstream_libxtst: needed lucid_libxtst: released (2:1.1.0-2ubuntu0.1) precise_libxtst: released (2:1.2.0-4ubuntu0.1) quantal_libxtst: released (2:1.2.1-1ubuntu0.12.10.1) raring_libxtst: released (2:1.2.1-1ubuntu0.13.04.1) devel_libxtst: not-affected (2:1.2.1-1+deb7u1)