CVE-2013-1872
published 2013-08-19CVE-2013-1872: The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.61%
83.7th percentile
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fs_visitor::remove_dead_constants function. NOTE: this issue might be related to CVE-2013-0796.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | mesa | < mesa 8.0.5-7 (bookworm) | mesa 8.0.5-7 (bookworm) |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | >= 0 < 8.0.5-7 | 8.0.5-7 |
| mesa3d | mesa | >= 0 < 8.0.5-7 | 8.0.5-7 |
| mesa3d | mesa | >= 0 < 8.0.5-7 | 8.0.5-7 |
| mesa3d | mesa | >= 0 < 8.0.5-7 | 8.0.5-7 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-847q-55hx-98vj: The Intel drivers in Mesa 8
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-1872 [CRITICAL] CWE-119 GHSA-847q-55hx-98vj: The Intel drivers in Mesa 8
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fs_visitor::remove_dead_constants function. NOTE: this issue might be related to CVE-2013-0796.
OSV
CVE-2013-1872: The Intel drivers in Mesa 8
osv·2013-08-19·CVSS 10.0
CVE-2013-1872 [CRITICAL] CVE-2013-1872: The Intel drivers in Mesa 8
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fs_visitor::remove_dead_constants function. NOTE: this issue might be related to CVE-2013-0796.
Ubuntu
Mesa vulnerabilities
vendor_ubuntu·2013-06-20·CVSS 6.8
CVE-2013-1872 [MEDIUM] Mesa vulnerabilities
Title: Mesa vulnerabilities
Summary: Mesa could be made to crash or run programs as your login if it received
specially crafted input.
It was discovered that Mesa incorrectly handled certain memory
calculations. An attacker could use this flaw to cause an application to
crash, or possibly execute arbitrary code. (CVE-2013-1872)
Ilja van Sprundel discovered that Mesa incorrectly handled certain memory
calculations. An attacker could use this flaw to cause an application to
crash, or possibly execute arbitrary code. (CVE-2013-1993)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
Mesa: Memory corruption (OOB read/write) on intel drivers
vendor_redhat·2013-05-29·CVSS 10.0
CVE-2013-1872 [CRITICAL] CWE-119 Mesa: Memory corruption (OOB read/write) on intel drivers
Mesa: Memory corruption (OOB read/write) on intel drivers
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fs_visitor::remove_dead_constants function. NOTE: this issue might be related to CVE-2013-0796.
Package: mesa (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-1872: mesa - The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to c...
vendor_debian·2013·CVSS 10.0
CVE-2013-1872 [CRITICAL] CVE-2013-1872: mesa - The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to c...
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fs_visitor::remove_dead_constants function. NOTE: this issue might be related to CVE-2013-0796.
Scope: local
bookworm: resolved (fixed in 8.0.5-7)
bullseye: resolved (fixed in 8.0.5-7)
forky: resolved (fixed in 8.0.5-7)
sid: resolved (fixed in 8.0.5-7)
trixie: resolved (fixed in 8.0.5-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers [fedora-all]
bugzilla·2013-06-03·CVSS 6.8
CVE-2013-1872 [MEDIUM] CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers [fedora-all]
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this is
Bugzilla
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers
bugzilla·2013-03-20·CVSS 6.8
CVE-2013-1872 [MEDIUM] CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers
An Out-of-bounds memory read / write flaw was found in Mesa. A remote attacker could use this flaw to crash an application linked against or, potentially, execute arbitrary code via an application linked against Mesa graphics libraries.
References:
https://bugs.freedesktop.org/show_bug.cgi?id=59429
https://code.google.com/p/chromium/issues/detail?id=169054 (private)
https://bugzilla.mozilla.org/show_bug.cgi?id=827106 (private)
Discussion:
Created mesa tracking bugs for this issue
Affects: fedora-all [bug 970010]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0897 https://rhn.redhat.com/errata/RHSA-2013-0897.html
http://advisories.mageia.org/MGASA-2013-0190.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0897.htmlhttp://www.debian.org/security/2013/dsa-2704http://www.securityfocus.com/bid/60285http://www.ubuntu.com/usn/USN-1888-1https://bugs.freedesktop.org/show_bug.cgi?id=59429https://bugzilla.redhat.com/show_bug.cgi?id=923584http://advisories.mageia.org/MGASA-2013-0190.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0897.htmlhttp://www.debian.org/security/2013/dsa-2704http://www.securityfocus.com/bid/60285http://www.ubuntu.com/usn/USN-1888-1https://bugs.freedesktop.org/show_bug.cgi?id=59429https://bugzilla.redhat.com/show_bug.cgi?id=923584
2013-08-19
Published