CVE-2013-1998

Description

Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.

Risk Information

Base Score
5.6
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.896

Associated Vulnerability

VulnerabilityOS Platform
X11 Input extension library (USN-1859-1) libxi6_1.6.0-0ubuntu2_i386.debLinux
X11 Input extension library (USN-1859-1) libxi6_1.6.0-0ubuntu2_amd64.debLinux
X11 Input extension library (USN-1859-1) libxi6_1.7.1.901-1ubuntu1~precise3_i386.debLinux
X11 Input extension library (USN-1859-1) libxi6_1.7.1.901-1ubuntu1~precise3_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234