// For flags

CVE-2013-4396

xorg-x11-server: use-after-free flaw when handling ImageText requests

Severity Score

6.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.

Vulnerabilidad de uso después de liberación en la función dolmageText en dix/dixfonts.c del módulo xorg-server anterior a la versión 1.14.4 en X.Org X11 permite a usuarios remotos autenticados provocar una denegación de servicio (cuelgue del demonio) o posiblemente ejecutar código arbitrario a través de una petición ImageText manipulada que provoque un fallo de reubicación de memoria.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-06-12 CVE Reserved
  • 2013-10-10 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
  • CWE-416: Use After Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.0
Search vendor "X" for product "X.org X11" and version "6.0"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.1
Search vendor "X" for product "X.org X11" and version "6.1"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.3
Search vendor "X" for product "X.org X11" and version "6.3"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.4
Search vendor "X" for product "X.org X11" and version "6.4"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.5.1
Search vendor "X" for product "X.org X11" and version "6.5.1"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.6
Search vendor "X" for product "X.org X11" and version "6.6"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.7
Search vendor "X" for product "X.org X11" and version "6.7"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.8
Search vendor "X" for product "X.org X11" and version "6.8"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.8.1
Search vendor "X" for product "X.org X11" and version "6.8.1"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.8.2
Search vendor "X" for product "X.org X11" and version "6.8.2"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
6.9.0
Search vendor "X" for product "X.org X11" and version "6.9.0"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.0
Search vendor "X" for product "X.org X11" and version "7.0"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.1
Search vendor "X" for product "X.org X11" and version "7.1"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.2
Search vendor "X" for product "X.org X11" and version "7.2"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.3
Search vendor "X" for product "X.org X11" and version "7.3"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.4
Search vendor "X" for product "X.org X11" and version "7.4"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.5
Search vendor "X" for product "X.org X11" and version "7.5"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.5
Search vendor "X" for product "X.org X11" and version "7.5"
rc1
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.6
Search vendor "X" for product "X.org X11" and version "7.6"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.6
Search vendor "X" for product "X.org X11" and version "7.6"
rc1
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.7
Search vendor "X" for product "X.org X11" and version "7.7"
-
Affected
X
Search vendor "X"
X.org X11
Search vendor "X" for product "X.org X11"
7.7
Search vendor "X" for product "X.org X11" and version "7.7"
rc1
Affected