« Volver al listado

CVE-2013-2066

Estado: ModificadaMedia (6.8)—

Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-2066",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-06-15T20:55:01.037",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106889.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00140.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.debian.org/security/2013/dsa-2674",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/05/23/3",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1867-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.x.org/wiki/Development/Security/Advisory-2013-05-23",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106889.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00140.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2013/dsa-2674",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/05/23/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1867-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.x.org/wiki/Development/Security/Advisory-2013-05-23",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function."
    },
    {
      "lang": "es",
      "value": "Un desbordamiento de búfer en libXv X.org v1.0.7 y anteriores permite causar una denegación de servicio a los servidores X (por caída de los mismos) y posiblemente ejecutar código de su elección a través de valores de longitud o de índice de la función XvQueryPortAttributes debidamente modificados."
    }
  ],
  "lastModified": "2026-06-16T23:52:41.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:x:libxv:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73DD3E1D-A540-493E-AC03-5AF562121106",
              "versionEndIncluding": "1.0.7"
            },
            {
              "criteria": "cpe:2.3:a:x:libxv:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "738DF3FA-3C69-4C60-B5F2-F6D32CD3630D"
            },
            {
              "criteria": "cpe:2.3:a:x:libxv:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EBFC510-E847-4C9A-8E99-3540A798F6B8"
            },
            {
              "criteria": "cpe:2.3:a:x:libxv:1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34B9A08A-1C29-49AB-BFB2-F1A57D05F1E5"
            },
            {
              "criteria": "cpe:2.3:a:x:libxv:1.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "566DCAE9-3FAA-4F5D-88A6-D06004B5B47B"
            },
            {
              "criteria": "cpe:2.3:a:x:libxv:1.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5BB54F7-5768-45B8-A8EB-8ED44D5E1588"
            },
            {
              "criteria": "cpe:2.3:a:x.org:libxv:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "711EAB64-279B-4EB1-B5DF-751AA47A842E"
            },
            {
              "criteria": "cpe:2.3:a:x.org:libxv:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F10B87F0-7A58-45AC-9621-E9AEA6ECD9BC"
            },
            {
              "criteria": "cpe:2.3:a:x.org:libxv:1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "098A760A-872F-49E0-A3F0-C8875433223E"
            },
            {
              "criteria": "cpe:2.3:a:x.org:libxv:1.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "381E664B-DDBA-445F-A4CC-B5C397CD89BF"
            },
            {
              "criteria": "cpe:2.3:a:x.org:libxv:1.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18E98D4E-961B-4F31-A254-732B261F026E"
            },
            {
              "criteria": "cpe:2.3:a:x.org:libxv:1.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEB33A37-C847-4812-8735-03E7C3D28CBB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}