CVE-2013-1872

medium
Published 2013-08-19 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access, related to the fs_visitor::remove_dead_constants function. NOTE: this issue might be related to CVE-2013-0796.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-1872

OS impact

OSVersionStatusFixed in
ubuntu ubuntu12.04affected
ubuntu ubuntu12.10affected
ubuntu ubuntu13.04affected
redhat rhel6.0affected
suse suse12.2affected
suse suse12.3affected
debian debianbookwormfixed8.0.5-7
debian debianbullseyefixed8.0.5-7
debian debianforkyfixed8.0.5-7
debian debiansidfixed8.0.5-7
debian debiantrixiefixed8.0.5-7

Application impact

VendorProductVersionsFixed
mesa3dmesa9.0
mesa3dmesa9.0.1
mesa3dmesa9.0.2
mesa3dmesa9.0.3
mesa3dmesa8.0
mesa3dmesa8.0.1
mesa3dmesa8.0.2
mesa3dmesa8.0.3
mesa3dmesa8.0.4
mesa3dmesa8.0.5

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.