CVE-2013-1872: Buffer Overflow
An Out-of-bounds memory read / write flaw was found in Mesa. A remote attacker could use this flaw to crash an application linked against or, potentially, execute arbitrary code via an application linked against Mesa graphics libraries.
References:
https://bugs.freedesktop.org/showbug.cgi?id=59429 https://code.google.com/p/chromium/issues/detail?id=169054 (private) https://bugzilla.mozilla.org/showbug.cgi?id=827106 (private)
Other sources
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fsvisitor::removedeadconstants function. NOTE: this issue might be related to CVE-2013-0796.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1872?
The severity of CVE-2013-1872 is high due to the potential for remote code execution and application crashes.
How do I fix CVE-2013-1872?
To fix CVE-2013-1872, update the Mesa graphics libraries to versions 9.0.4 or later.
What applications are affected by CVE-2013-1872?
CVE-2013-1872 affects applications linked against vulnerable versions of Mesa 3D graphics libraries.
Can CVE-2013-1872 be exploited remotely?
Yes, CVE-2013-1872 can be exploited remotely by attackers to execute arbitrary code.
What versions of Mesa are affected by CVE-2013-1872?
Versions 8.0 to 9.0.3 of Mesa 3D are affected by CVE-2013-1872.