CVE-2013-1993
published 2013-06-15CVE-2013-1993: Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.69%
84.3th percentile
Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mesa | < mesa 8.0.5-6 (bookworm) | mesa 8.0.5-6 (bookworm) |
| mesa3d | mesa | <= 9.1.1 | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | — | — |
| mesa3d | mesa | >= 0 < 8.0.5-6 | 8.0.5-6 |
| mesa3d | mesa | >= 0 < 8.0.5-6 | 8.0.5-6 |
| mesa3d | mesa | >= 0 < 8.0.5-6 | 8.0.5-6 |
| mesa3d | mesa | >= 0 < 8.0.5-6 | 8.0.5-6 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mesa vulnerabilities
vendor_ubuntu·2013-06-20·CVSS 6.8
CVE-2013-1872 [MEDIUM] Mesa vulnerabilities
Title: Mesa vulnerabilities
Summary: Mesa could be made to crash or run programs as your login if it received
specially crafted input.
It was discovered that Mesa incorrectly handled certain memory
calculations. An attacker could use this flaw to cause an application to
crash, or possibly execute arbitrary code. (CVE-2013-1872)
Ilja van Sprundel discovered that Mesa incorrectly handled certain memory
calculations. An attacker could use this flaw to cause an application to
crash, or possibly execute arbitrary code. (CVE-2013-1993)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
Mesa: Multiple integer overflows leading to heap-based bufer overflows
vendor_redhat·2013-05-23·CVSS 6.8
CVE-2013-1993 [MEDIUM] CWE-190 Mesa: Multiple integer overflows leading to heap-based bufer overflows
Mesa: Multiple integer overflows leading to heap-based bufer overflows
Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.
Debian
CVE-2013-1993: mesa - Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X ser...
vendor_debian·2013·CVSS 6.8
CVE-2013-1993 [MEDIUM] CVE-2013-1993: mesa - Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X ser...
Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.
Scope: local
bookworm: resolved (fixed in 8.0.5-6)
bullseye: resolved (fixed in 8.0.5-6)
forky: resolved (fixed in 8.0.5-6)
sid: resolved (fixed in 8.0.5-6)
trixie: resolved (fixed in 8.0.5-6)
GHSA
GHSA-4j5x-8p5g-fw48: Multiple integer overflows in X
ghsa_unreviewed·2022-05-17
CVE-2013-1993 [MEDIUM] GHSA-4j5x-8p5g-fw48: Multiple integer overflows in X
Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.
OSV
CVE-2013-1993: Multiple integer overflows in X
osv·2013-06-15·CVSS 6.8
CVE-2013-1993 [MEDIUM] CVE-2013-1993: Multiple integer overflows in X
Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2013-0190.htmlhttp://lists.freedesktop.org/archives/mesa-dev/2013-May/039720.htmlhttp://lists.freedesktop.org/archives/mesa-dev/2013-May/039722.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00007.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0897.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0898.htmlhttp://www.debian.org/security/2013/dsa-2678http://www.mandriva.com/security/advisories?name=MDVSA-2013:181http://www.openwall.com/lists/oss-security/2013/05/23/3http://www.ubuntu.com/usn/USN-1888-1http://www.x.org/wiki/Development/Security/Advisory-2013-05-23http://advisories.mageia.org/MGASA-2013-0190.htmlhttp://lists.freedesktop.org/archives/mesa-dev/2013-May/039720.htmlhttp://lists.freedesktop.org/archives/mesa-dev/2013-May/039722.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00007.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0897.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0898.htmlhttp://www.debian.org/security/2013/dsa-2678http://www.mandriva.com/security/advisories?name=MDVSA-2013:181http://www.openwall.com/lists/oss-security/2013/05/23/3http://www.ubuntu.com/usn/USN-1888-1http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
2013-06-15
Published