Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libx11 | Jul 30, 2024 | Apr 16, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 9, 2013 |
| Suse | — | Upgrade xorg-x11-libx11Upgrade sle-sdk-releaseUpgrade xorg-x11-libX11-develUpgrade xorg-x11-libX11-devel-32bitUpgrade xorg-x11-libx11-32bitUpgrade xorg-x11-libX11-x86 | Nov 17, 2015 | Apr 16, 2015 |
| Ubuntu | — | Upgrade libx11-devUpgrade libxrender1 | Nov 8, 2024 | Apr 16, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub