This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours
Bug 959046 - (CVE-2013-1982) CVE-2013-1982 libXext: Multiple integer overflows leading to heap-based buffer-overflows
CVE-2013-1982 libXext: Multiple integer overflows leading to heap-based buffe...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Peter Hutterer
impact=moderate,public=20130523,repor...
: Reopened, Security
Depends On: 966684 1078022
Blocks: 959130 1101912
  Show dependency treegraph
 
Reported: 2013-05-03 01:02 EDT by Huzaifa S. Sidhpurwala
Modified: 2014-10-17 03:37 EDT (History)
5 users (show)

See Also:
Fixed In Version: libXext 1.3.2
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-10-16 02:08:19 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Huzaifa S. Sidhpurwala 2013-05-03 01:02:35 EDT
Several integer overflow flaws leading to heap-based buffer overflows were found in libXext, an X.Org X11 libXext runtime library.

       Affected functions:  XcupGetReservedColormapEntries(),
          XcupStoreColors(), XdbeGetVisualInfo(), XeviGetVisualInfo(),
          XShapeGetRectangles(), XSyncListSystemCounters()
Comment 1 Peter Hutterer 2013-05-05 21:28:09 EDT
Created attachment 743923 [details]
0044-Use-_XEatDataWords-to-avoid-overflow-of-rep.length-b.patch
Comment 2 Peter Hutterer 2013-05-05 21:29:09 EDT
Created attachment 743924 [details]
0045-integer-overflow-and-signedness-issue-in-XcupGetRese.patch
Comment 3 Peter Hutterer 2013-05-05 21:30:31 EDT
Created attachment 743926 [details]
0046-integer-overflow-and-signedness-issue-in-XcupStoreCo.patch
Comment 4 Peter Hutterer 2013-05-05 21:31:07 EDT
Created attachment 743927 [details]
0047-several-integer-overflows-in-XdbeGetVisualInfo.patch
Comment 5 Peter Hutterer 2013-05-05 21:31:34 EDT
Created attachment 743928 [details]
0048-integer-overflow-in-XeviGetVisualInfo.patch
Comment 6 Peter Hutterer 2013-05-05 21:32:08 EDT
Created attachment 743929 [details]
0049-integer-overflow-in-XShapeGetRectangles.patch
Comment 7 Peter Hutterer 2013-05-05 21:36:15 EDT
Created attachment 743930 [details]
0050-integer-overflow-in-XSyncListSystemCounters.patch
Comment 15 Jan Lieskovsky 2013-05-23 11:27:23 EDT
Public via:
  http://www.openwall.com/lists/oss-security/2013/05/23/3
Comment 17 Jan Lieskovsky 2013-05-23 12:46:20 EDT
These issues affect the versions of the libXext package, as shipped with Fedora release of 17 and 18. Please schedule an update.
Comment 18 Jan Lieskovsky 2013-05-23 12:48:20 EDT
Created libXext tracking bugs for this issue

Affects: fedora-all [bug 966684]
Comment 19 Jan Lieskovsky 2013-05-23 13:03:09 EDT
External References:

http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
Comment 20 Peter Hutterer 2013-05-27 23:05:16 EDT
All packages in stable, closing.
Comment 22 Fedora Update System 2013-06-02 23:02:33 EDT
libXext-1.3.1-3.20130524gitdfe6e1f3b.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 23 Huzaifa S. Sidhpurwala 2013-06-04 23:31:17 EDT
This issue affects the version of libXext as shipped with Red Hat Enterprise Linux 5 and 6.
Comment 24 Huzaifa S. Sidhpurwala 2013-06-04 23:45:41 EDT
Statement:

This issue affects the libXext package in Red Hat Enterprise Linux 5. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not planned to be fixed in Red Hat Enterprise Linux 5 as it is now in Production 3 Phase of the support and maintenance life cycle: https://access.redhat.com/support/policy/updates/errata/
Comment 25 Fedora Update System 2013-06-07 23:41:40 EDT
libXext-1.3.2-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 27 errata-xmlrpc 2014-10-14 01:05:01 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2014:1436 https://rhn.redhat.com/errata/RHSA-2014-1436.html

Note You need to log in before you can comment on or make changes to this bug.