PT-2007-1098 · Gentoo+2 · Gentoo Linux+2
Published
2007-10-05
·
Updated
2024-06-15
·
CVE-2007-4568
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
X.Org X Font Server (xfs) versions prior to 1.0.5
Gentoo Linux xfs package versions prior to 1.0.5
Description:
The issue is related to an integer overflow in the build range function, allowing context-dependent attackers to execute arbitrary code via crafted size values in QueryXBitmaps and QueryXExtents protocol requests, which triggers a heap-based buffer overflow. Additionally, there are multiple vulnerabilities in the xfs package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations:
For X.Org X Font Server (xfs) versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue.
For Gentoo Linux xfs package versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue.
As a temporary workaround, consider restricting access to the QueryXBitmaps and QueryXExtents protocol requests until a patch is available.
Fix
Buffer Overflow
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gentoo Linux
Red Hat
X.Org X Font Server