CVE-2013-1984

Description

Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (5) XIGetProperty, (6) XIGetSelectedEvents, (7) XGetDeviceProperties, and (8) XListInputDevices functions.

Risk Information

Base Score
5.6
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.904

Associated Vulnerability

VulnerabilityOS Platform
X11 Input extension library (USN-1859-1) libxi6_1.6.0-0ubuntu2_i386.debLinux
X11 Input extension library (USN-1859-1) libxi6_1.6.0-0ubuntu2_amd64.debLinux
X11 Input extension library (USN-1859-1) libxi6_1.7.1.901-1ubuntu1~precise3_i386.debLinux
X11 Input extension library (USN-1859-1) libxi6_1.7.1.901-1ubuntu1~precise3_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234