PublicDateAtUSN: 2013-05-23 15:00:00 UTC Candidate: CVE-2013-2064 CRD: 2013-05-23 15:00:00 UTC PublicDate: 2013-06-15 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2064 http://www.x.org/wiki/Development/Security/Advisory-2013-05-23 http://www.debian.org/security/2013/dsa-2686 https://ubuntu.com/security/notices/USN-1855-1 Description: Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Ilja van Sprundel Assigned-to: mdeslaur CVSS: Patches_libxcb: upstream: http://cgit.freedesktop.org/xcb/libxcb/commit/?id=1b33867fa996034deb50819ae54640be501f8d20 (1/1) upstream_libxcb: pending (1.8.1-2+deb7u1,1.9.1) lucid_libxcb: released (1.5-2ubuntu0.1) precise_libxcb: released (1.8.1-1ubuntu0.2) quantal_libxcb: released (1.8.1-1ubuntu1.1) raring_libxcb: released (1.8.1-2ubuntu2.1) devel_libxcb: released (1.8.1-2ubuntu3)