---
title: "CVE-2013-1997\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1997?format=md
keywords: index, follow
---

# CVE-2013-1997

Publication date 23 May 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier
allow X servers to cause a denial of service (crash) and possibly execute
arbitrary code via crafted length or index values to the (1)
XAllocColorCells, (2) \_XkbReadGetDeviceInfoReply, (3) \_XkbReadGeomShapes,
(4) \_XkbReadGetGeometryReply, (5) \_XkbReadKeySyms, (6) \_XkbReadKeyActions,
(7) \_XkbReadKeyBehaviors, (8) \_XkbReadModifierMap, (9)
\_XkbReadExplicitComponents, (10) \_XkbReadVirtualModMap, (11)
\_XkbReadGetNamesReply, (12) \_XkbReadGetMapReply, (13) \_XimXGetReadData,
(14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libx11 | 13.04 raring | Fixed 2:1.5.0-1ubuntu1.1 |
| 12.10 quantal | Fixed 2:1.5.0-1ubuntu0.1 |
| 12.04 LTS precise | Fixed 2:1.4.99.1-0ubuntu2.1 |
| 10.04 LTS lucid | Fixed 2:1.3.2-1ubuntu3.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2013-1997?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| libx11 | * Upstream:   [?id=cdd](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=cddc4e7e3cb4b9b7ad25f8591971a86901c249f2) * Upstream:   [?id=f29](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=f293659d5a4024bda386305bb7ebeb4647c40934) * Upstream:   [?id=bff](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=bff938b9fe1629cbacb726509edfa2a3840b7207) * Upstream:   [?id=59a](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=59ae16a00d18588e98af57d26e442af8ea42b7aa) * Upstream:   [?id=fd7](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=fd7d4956bc7a1c4b5c38661b12777ebee4d685d9) * Upstream:   [?id=006](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=00626c3830b869259098985afa38933d77ccec72) * Upstream:   [?id=06c](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=06c086e8a1d8374ea9a95ff989f053c96bb1bdca) * Upstream:   [?id=e56](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=e56a2ada719c5cfac5ed61a52a80ade86c0f5957) * Upstream:   [?id=4d7](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=4d7c422a37eb9617fb22f8e37527c2b34b105665) * Upstream:   [?id=2df](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=2df882eeb3a70256170127a746a9ba26376599a1) * Upstream:   [?id=de2](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=de2e6c322c4aca22856b380f67f8e488e7510015) * Upstream:   [?id=b9b](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=b9ba832401734e1cbd30a930c0d11d850293f3f9) * Upstream:   [?id=0c4](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=0c404db6a92dc2c198328bf586c02d8abbe02013) * Upstream:   [?id=8d5](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=8d5936594993921acdfec778dd8f41b555e2543a) * Upstream:   [?id=db1](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=db1b1c871da29aa0545182bf888df81627f165a5) * Upstream:   [?id=e1b](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=e1b457beb8d4e831ef44279dada6c475cb955738) * Upstream:   [?id=a3b](http://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=a3bdd2b090915fe0163b062f0e6576fe05dd332e) |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1997)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1997)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1997)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1997)

### Related Ubuntu Security Notices (USN)

+ [USN-1854-1](https://usn.ubuntu.com/USN-1854-1)
+ libx11 vulnerabilities
+ 5 June 2013

### Other references

* <http://www.x.org/wiki/Development/Security/Advisory-2013-05-23>
* <http://www.debian.org/security/2013/dsa-2693>
* <https://www.cve.org/CVERecord?id=CVE-2013-1997>
