PT-2001-2108 · Xterm+2 · Xterm+2
Published
2001-09-22
·
Updated
2017-12-19
·
CVE-2001-0955
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
XFree86 versions prior to 4.2.0
Description
The issue is related to a buffer overflow in the fbglyph.c file, specifically with glyph clipping for large origins. This can be exploited by attackers to cause a denial of service and potentially gain privileges. The exploitation could occur through a large number of characters, possibly via the web page search form of KDE Konqueror or from an xterm command with a long title.
Recommendations
For XFree86 versions prior to 4.2.0, update to version 4.2.0 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kde Konqueror
Xfree86
Xterm