SB2014091808 - Amazon Linux AMI update for libxcb
Published: September 18, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2013-2064)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
Remediation
Install update from vendor's website.