PT-2014-1832 · X.Org Foundation+5 · Libxfont+5

Publicado

2014-05-13

·

Atualizado

2018-10-09

·

CVE-2014-0210

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libXfont versions prior to 1.4.8 libXfont versions 1.4.9x prior to 1.4.99.901
Description The issue involves multiple buffer overflows in the libXfont package, allowing remote font servers to execute arbitrary code via crafted xfs protocol replies to various functions, including fs recv conn setup, fs read open font, fs read query info, fs read extent info, fs read glyphs, fs read list, and fs read list info. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely.
Recommendations For libXfont versions prior to 1.4.8, update to version 1.4.8 or later. For libXfont versions 1.4.9x prior to 1.4.99.901, update to version 1.4.99.901 or later. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available. Avoid using the vulnerable libXfont package for remote font server connections until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1649
BDU:2015-06368
BDU:2015-06369
BDU:2015-06370
BDU:2015-06371
BDU:2015-06372
BDU:2015-06373
BDU:2015-06374
BDU:2015-09764
CESA-2014_1870
CVE-2014-0210
DSA-2927-1
MGASA-2014-0278
OPENSUSE-SU-2024:10299-1
RHSA-2014:1870
RHSA-2014:1893
RHSA-2014_1870
RHSA-2014_1893
SUSE-SU-2015:0674-1
USN-2211-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxfont