CVE-2013-6424: Integer Underflow
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xorg-serverto a version that resolves this vulnerability.Fixed in 2:1.20.11-1+deb11u13Fixed in 2:1.20.11-1+deb11u15Fixed in 2:21.1.7-3+deb12u9Fixed in 2:21.1.16-1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2013-6424.
What is the severity of CVE-2013-6424?
The severity of CVE-2013-6424 is medium.
Which software is affected by CVE-2013-6424?
The affected software includes Pixman, Debian Linux 6.0 and 7.0, OpenSUSE 12.2, 12.3, and 13.1, and Ubuntu Linux 12.04, 14.04, and 14.10.
How can a context-dependent attacker exploit CVE-2013-6424?
A context-dependent attacker can exploit CVE-2013-6424 to cause a denial of service (crash) by providing a negative value for the bottom parameter in the xTrapezoidValid macro.
Is there a fix available for CVE-2013-6424?
Yes, there are fixes available for CVE-2013-6424. Please refer to the references provided for more information on the available patches.