PT-2007-1098 · Gentoo+2 · Gentoo Linux+2

Published

2007-10-05

·

Updated

2024-06-15

·

CVE-2007-4568

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: X.Org X Font Server (xfs) versions prior to 1.0.5 Gentoo Linux xfs package versions prior to 1.0.5
Description: The issue is related to an integer overflow in the build range function, allowing context-dependent attackers to execute arbitrary code via crafted size values in QueryXBitmaps and QueryXExtents protocol requests, which triggers a heap-based buffer overflow. Additionally, there are multiple vulnerabilities in the xfs package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations: For X.Org X Font Server (xfs) versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue. For Gentoo Linux xfs package versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the QueryXBitmaps and QueryXExtents protocol requests until a patch is available.

Fix

Buffer Overflow

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09581
CVE-2007-4568
DSA-1385-1
OPENSUSE-SU-2024:11524-1
RHSA-2008:0029
RHSA-2008:0030
RHSA-2008_0030

Affected Products

Gentoo Linux
Red Hat
X.Org X Font Server