CVE-2013-2004
Description
The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.393
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| X11 client-side library (USN-1854-1) libx11-6_1.4.99.1-0ubuntu2_i386.deb | Linux |
| X11 client-side library (USN-1854-1) libx11-6_1.4.99.1-0ubuntu2_amd64.deb | Linux |
| X11 client-side library (USN-1854-1) libx11-6_1.4.99.1-0ubuntu2.3_i386.deb | Linux |
| X11 client-side library (USN-1854-1) libx11-6_1.4.99.1-0ubuntu2.3_amd64.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234