PT-2003-1122 · Red Hat+1 · Red Hat+1

Blexim

·

Published

2003-09-03

·

Updated

2016-10-18

·

CVE-2003-0730

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86-4.3.0 XFree86-4.2.1 XFree86-4.1.0 XFree86-base-fonts versions 4.3.0 through 4.1.0 XFree86-ISO8859-9-75dpi-fonts versions 4.3.0 through 4.1.0 XFree86-ISO8859-15-100dpi-fonts versions 4.3.0 through 4.1.0 XFree86-100dpi-fonts versions 4.3.0 through 4.1.0 XFree86-75dpi-fonts versions 4.3.0 through 4.1.0 XFree86-devel versions 4.3.0 through 4.1.0 XFree86-doc versions 4.3.0 through 4.1.0 XFree86-libs versions 4.3.0 through 4.1.0 XFree86-Mesa-libGL versions 4.3.0 through 4.1.0 XFree86-Mesa-libGLU versions 4.3.0 through 4.1.0 XFree86-sdk versions 4.3.0 XFree86-tools versions 4.3.0 through 4.1.0 XFree86-twm versions 4.3.0 through 4.1.0 XFree86-xauth versions 4.3.0 through 4.1.0 XFree86-xdm versions 4.3.0 through 4.1.0 XFree86-Xnest versions 4.3.0 through 4.1.0 XFree86-xfs versions 4.3.0 through 4.1.0 XFree86-Xvfb versions 4.3.0 through 4.1.0 XFree86-font-utils versions 4.3.0 through 4.1.0 XFree86-truetype-fonts versions 4.3.0 through 4.1.0 XFree86-cyrillic-fonts versions 4.3.0 through 4.1.0 XFree86-ISO8859-2-75dpi-fonts versions 4.3.0 through 4.1.0 XFree86-ISO8859-2-100dpi-fonts versions 4.3.0 through 4.1.0 XFree86-ISO8859-14-75dpi-fonts version 4.3.0 XFree86-ISO8859-14-100dpi-fonts version 4.3.0 XFree86-ISO8859-15-75dpi-fonts versions 4.3.0 through 4.1.0
Description The issue affects the XFree86 package in Red Hat Linux, allowing remote attackers to compromise confidentiality, integrity, and availability of protected information. The vulnerability can be exploited through multiple integer overflows in the font libraries, leading to a denial of service or the execution of arbitrary code via heap-based and stack-based buffer overflow attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08248
BDU:2015-08249
BDU:2015-08250
BDU:2015-08251
BDU:2015-08252
BDU:2015-08253
BDU:2015-08254
BDU:2015-08255
BDU:2015-08256
BDU:2015-08257
BDU:2015-08258
BDU:2015-08259
BDU:2015-08261
BDU:2015-08262
BDU:2015-08263
BDU:2015-08264
BDU:2015-08265
BDU:2015-08266
BDU:2015-08267
BDU:2015-08268
BDU:2015-08269
BDU:2015-08270
BDU:2015-08271
BDU:2015-08272
BDU:2015-08273
BDU:2015-08274
BDU:2015-08276
BDU:2015-08277
BDU:2015-08278
BDU:2015-08279
BDU:2015-08280
BDU:2015-08281
BDU:2015-08282
BDU:2015-08283
BDU:2015-08284
BDU:2015-08285
BDU:2015-08286
BDU:2015-08287
BDU:2015-08288
BDU:2015-08289
BDU:2015-08290
BDU:2015-08291
BDU:2015-08317
BDU:2015-08318
BDU:2015-08319
BDU:2015-08320
BDU:2015-08321
BDU:2015-08322
BDU:2015-08323
BDU:2015-08324
BDU:2015-08325
BDU:2015-08326
BDU:2015-08327
BDU:2015-08328
BDU:2015-08329
BDU:2015-08330
BDU:2015-08331
BDU:2015-08332
BDU:2015-08333
BDU:2015-08334
BDU:2015-08335
BDU:2015-08336
BDU:2015-08337
BDU:2015-08338
BDU:2015-08339
BDU:2015-08340
BDU:2015-08341
BDU:2015-08342
BDU:2015-08343
BDU:2015-08344
BDU:2015-08345
BDU:2015-08346
BDU:2015-08347
BDU:2015-08348
BDU:2015-08349
BDU:2015-08350
CVE-2003-0730
DSA-380

Affected Products

Red Hat
Xfree86