{"id":"CVE-2013-2005","details":"X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.","modified":"2026-04-16T01:39:21.882157840Z","published":"2013-06-15T20:55:01Z","withdrawn":"2026-01-27T04:13:08.713883Z","related":["openSUSE-SU-2024:10419-1"],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2013/dsa-2680"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1865-1"},{"type":"ADVISORY","url":"http://www.x.org/wiki/Development/Security/Advisory-2013-05-23"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106785.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2013-06/msg00138.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/05/23/3"},{"type":"WEB","url":"http://www.securityfocus.com/bid/60133"}],"schema_version":"1.7.3"}