PT-2007-1098 · Gentoo+2 · Gentoo Linux+2

Publicado

2007-10-05

·

Atualizado

2024-06-15

·

CVE-2007-4568

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: X.Org X Font Server (xfs) versions prior to 1.0.5 Gentoo Linux xfs package versions prior to 1.0.5
Description: The issue is related to an integer overflow in the build range function, allowing context-dependent attackers to execute arbitrary code via crafted size values in QueryXBitmaps and QueryXExtents protocol requests, which triggers a heap-based buffer overflow. Additionally, there are multiple vulnerabilities in the xfs package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations: For X.Org X Font Server (xfs) versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue. For Gentoo Linux xfs package versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the QueryXBitmaps and QueryXExtents protocol requests until a patch is available.

Correção

Buffer Overflow

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09581
CVE-2007-4568
DSA-1385-1
OPENSUSE-SU-2024:11524-1
RHSA-2008:0029
RHSA-2008:0030
RHSA-2008_0030

Produtos afetados

Gentoo Linux
Red Hat
X.Org X Font Server