CVE Vulnerabilities

CVE-2013-4396

Published: Oct 10, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
7.4 IMPORTANT
AV:A/AC:M/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.

Affected Software

NameVendorStart VersionEnd Version
X.org_x11X6.0 (including)6.0 (including)
X.org_x11X6.1 (including)6.1 (including)
X.org_x11X6.3 (including)6.3 (including)
X.org_x11X6.4 (including)6.4 (including)
X.org_x11X6.5.1 (including)6.5.1 (including)
X.org_x11X6.6 (including)6.6 (including)
X.org_x11X6.7 (including)6.7 (including)
X.org_x11X6.8 (including)6.8 (including)
X.org_x11X6.8.1 (including)6.8.1 (including)
X.org_x11X6.8.2 (including)6.8.2 (including)
X.org_x11X6.9.0 (including)6.9.0 (including)
X.org_x11X7.0 (including)7.0 (including)
X.org_x11X7.1 (including)7.1 (including)
X.org_x11X7.2 (including)7.2 (including)
X.org_x11X7.3 (including)7.3 (including)
X.org_x11X7.4 (including)7.4 (including)
X.org_x11X7.5 (including)7.5 (including)
X.org_x11X7.5-rc1 (including)7.5-rc1 (including)
X.org_x11X7.6 (including)7.6 (including)
X.org_x11X7.6-rc1 (including)7.6-rc1 (including)
X.org_x11X7.7 (including)7.7 (including)
X.org_x11X7.7-rc1 (including)7.7-rc1 (including)
Red Hat Enterprise Linux 5RedHatxorg-x11-server-0:1.1.1-48.101.el5_10.1*
Red Hat Enterprise Linux 6RedHatxorg-x11-server-0:1.13.0-11.1.el6_4.2*
Xorg-serverUbuntudevel*
Xorg-serverUbuntulucid*
Xorg-serverUbuntuprecise*
Xorg-serverUbuntuquantal*
Xorg-serverUbunturaring*
Xorg-serverUbuntuupstream*
Xorg-server-lts-quantalUbuntuprecise*
Xorg-server-lts-raringUbuntuprecise*

References