CVE-2013-7439
libx11 - security update
EPSS 4.3%
描述
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.
如何修補 CVE-2013-7439
要修補 CVE-2013-7439,請將受影響套件升級到下列已修補版本。
- Debian/libx11—升級至 2:1.6.0-1 或更新版本
- Debian/libx11—升級至 2:1.3.3-4+squeeze2 或更新版本
- Debian/libx11—升級至 2:1.5.0-1+deb7u2 或更新版本
CVE-2013-7439 正在被利用嗎?
低 — EPSS 為 4.3%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2:1.6.0-1
- from 0, < 2:1.3.3-4+squeeze2
- from 0, < 2:1.5.0-1+deb7u2