Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XcupGetReservedColormapEntries, (2) XcupStoreColors, (3) XdbeGetVisualInfo, (4) XeviGetVisualInfo, (5) XShapeGetRectangles, and (6) XSyncListSystemCounters functions.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-1857-1 | vendor advisory |
http://www.openwall.com/lists/oss-security/2013/05/23/3 | mailing list |
http://lists.opensuse.org/opensuse-updates/2013-06/msg00139.html | vendor advisory |
http://www.debian.org/security/2013/dsa-2682 | vendor advisory |
http://www.x.org/wiki/Development/Security/Advisory-2013-05-23 | patch vendor advisory |