CVE-2013-1987: Canonical Ubuntu Linux

Medium severity, CVSS 6.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.04 only
  • Opensuse Opensuse: version 12.2 only; version 12.3 only
  • X Libxrender: up to and including 0.9.7; version 0.9.1 only; version 0.9.2 only; version 0.9.3 only; version 0.9.4 only; version 0.9.5 only; …

Published 2013-06-15. Last modified 2026-06-16.