CVE-2013-6424
published 2014-01-18CVE-2013-6424: Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.88%
85.3th percentile
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:1.14.2.901-1 (bookworm) | xorg-server 2:1.14.2.901-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| pixman | pixman | < 0.31.2 | 0.31.2 |
| x.org | xorg-server | >= 0 < 2:1.14.2.901-1 | 2:1.14.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.14.2.901-1 | 2:1.14.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.14.2.901-1 | 2:1.14.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.14.2.901-1 | 2:1.14.2.901-1 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.7 | 2:1.15.1-0ubuntu2.7 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2015-02-17·CVSS 5.0
CVE-2013-6424 [MEDIUM] X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that the X.Org X server incorrectly handled certain
trapezoids. An attacker able to connect to an X server, either locally or
remotely, could use this issue to possibly crash the server. This issue
only affected Ubuntu 12.04 LTS. (CVE-2013-6424)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: integer underflow when handling trapezoids
vendor_redhat·2013-07-16·CVSS 5.0
CVE-2013-6424 [MEDIUM] CWE-190 xorg-x11-server: integer underflow when handling trapezoids
xorg-x11-server: integer underflow when handling trapezoids
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Package: xorg-x11-server (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6424: xorg-server - Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allo...
vendor_debian·2013·CVSS 5.0
CVE-2013-6424 [MEDIUM] CVE-2013-6424: xorg-server - Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allo...
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Scope: local
bookworm: resolved (fixed in 2:1.14.2.901-1)
bullseye: resolved (fixed in 2:1.14.2.901-1)
forky: resolved (fixed in 2:1.14.2.901-1)
sid: resolved (fixed in 2:1.14.2.901-1)
trixie: resolved (fixed in 2:1.14.2.901-1)
GHSA
GHSA-vp3j-rhgw-hr9f: Integer underflow in the xTrapezoidValid macro in render/picture
ghsa_unreviewed·2022-05-13
CVE-2013-6424 [MEDIUM] CWE-191 GHSA-vp3j-rhgw-hr9f: Integer underflow in the xTrapezoidValid macro in render/picture
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
OSV
xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
osv·2015-02-17·CVSS 5.0
CVE-2015-0255 [MEDIUM] xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that the X.Org X server incorrectly handled certain
trapezoids. An attacker able to connect to an X server, either locally or
remotely, could use this issue to possibly crash the server. This issue
only affected Ubuntu 12.04 LTS. (CVE-2013-6424)
OSV
CVE-2013-6424: Integer underflow in the xTrapezoidValid macro in render/picture
osv·2014-01-18·CVSS 5.0
CVE-2013-6424 [MEDIUM] CVE-2013-6424: Integer underflow in the xTrapezoidValid macro in render/picture
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6424 xorg-x11-server: integer underflow when handling trapezoids [fedora-all]
bugzilla·2013-12-17·CVSS 5.0
CVE-2013-6424 [MEDIUM] CVE-2013-6424 xorg-x11-server: integer underflow when handling trapezoids [fedora-all]
CVE-2013-6424 xorg-x11-server: integer underflow when handling trapezoids [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2013-6424 xorg-x11-server: integer underflow when handling trapezoids
bugzilla·2013-12-04·CVSS 5.0
CVE-2013-6424 [MEDIUM] CVE-2013-6424 xorg-x11-server: integer underflow when handling trapezoids
CVE-2013-6424 xorg-x11-server: integer underflow when handling trapezoids
An integer underflow flaw was found in the X.Org server when handling trapezoids. A malicious, authorized client could use this flaw to crash the X.Org server.
References:
http://seclists.org/oss-sec/2013/q4/399
http://patchwork.freedesktop.org/patch/14769/
Discussion:
Note:
On Further investigation it was discovered that there may be a possibility of arbitrary user controlled code execution in this particular flaw. Security impact and the cvss2 scoring has been adjusted accordingly.
---
Created xorg-x11-server tracking bugs for this issue:
Affects: fedora-all [bug 1043751]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2013:1868 htt
http://lists.opensuse.org/opensuse-updates/2013-12/msg00127.htmlhttp://lists.x.org/archives/xorg-devel/2013-October/037996.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1868.htmlhttp://www.debian.org/security/2013/dsa-2822http://www.openwall.com/lists/oss-security/2013/12/03/8http://www.openwall.com/lists/oss-security/2013/12/04/8http://www.ubuntu.com/usn/USN-2500-1https://bugs.freedesktop.org/show_bug.cgi?id=67484https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/1197921https://security.gentoo.org/glsa/201701-64https://security.gentoo.org/glsa/201710-30http://lists.opensuse.org/opensuse-updates/2013-12/msg00127.htmlhttp://lists.x.org/archives/xorg-devel/2013-October/037996.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1868.htmlhttp://www.debian.org/security/2013/dsa-2822http://www.openwall.com/lists/oss-security/2013/12/03/8http://www.openwall.com/lists/oss-security/2013/12/04/8http://www.ubuntu.com/usn/USN-2500-1https://bugs.freedesktop.org/show_bug.cgi?id=67484https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/1197921https://security.gentoo.org/glsa/201701-64https://security.gentoo.org/glsa/201710-30
2014-01-18
Published