CVE-2013-1056
published 2013-10-28CVE-2013-1056: X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors…
PriorityP49low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.34%
26.4th percentile
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | xorg-server | — | — |
| x.org | xorg-server | >= 0 < 2:1.14.4-1ubuntu2 | 2:1.14.4-1ubuntu2 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_redhat2.1LOW
vendor_debian1.9LOW
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xm67-p6rp-wvcr: X
ghsa_unreviewed·2022-05-17
CVE-2013-1056 [LOW] GHSA-xm67-p6rp-wvcr: X
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
OSV
CVE-2013-1056: X
osv·2013-10-16·CVSS 1.9
CVE-2013-1056 [LOW] CVE-2013-1056: X
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2013-10-17·CVSS 1.9
CVE-2013-1056 [LOW] X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: The X.Org X server could be made to crash or run programs as an
administrator if it received specially crafted input.
Pedro Ribeiro discovered that the X.Org X server incorrectly handled
memory operations when handling ImageText requests. An attacker could use
this issue to cause X.Org to crash, or to possibly execute arbitrary code.
(CVE-2013-4396)
It was discovered that non-root X.Org X servers such as Xephyr incorrectly
used cached xkb files. A local attacker could use this flaw to cause a xkb
cache file to be loaded by another user, resulting in a denial of service.
(CVE-2013-1056)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: local DoS vulnerability
vendor_redhat·2013-10-17·CVSS 1.9
CVE-2013-1056 [LOW] xorg-x11-server: local DoS vulnerability
xorg-x11-server: local DoS vulnerability
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
Statement: Not vulnerable. This issue did not affect the versions of xorg-x11-server as shipped with Red Hat Enterprise Linux 5 and 6 as our products did not include the vulnerable patch.
The vulnerability was introduced due to a Ubuntu specific patch, which we never used with the xorg-x11-server we ship with our products.
Package: xorg-x11-server (Red Hat Enterprise Linux 5) - Not affected
Package: xorg-x11-server (Red Hat Enterprise Linux 6) - Not affected
Package: xorg-x11-server (Red Hat Enterprise Linux 7) - Not affected
Red Hat
kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
vendor_redhat·2013-06-03·CVSS 2.1
CVE-2013-2076 [LOW] kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect R
Debian
CVE-2013-1056: xorg-server - X.org X server 1.13.3 and earlier, when not run as root, allows local users to c...
vendor_debian·2013·CVSS 1.9
CVE-2013-1056 [LOW] CVE-2013-1056: xorg-server - X.org X server 1.13.3 and earlier, when not run as root, allows local users to c...
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2013-10-28
Published