CVE-2013-2004: X LIBX11

Medium severity, CVSS 6.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.

Affected products

  • X LIBX11: up to and including 1.5.99.901; version 1.5.0 only

Published 2013-06-15. Last modified 2026-06-16.