PT-2007-7521 · Freetype+4 · Freetype+5

Greg Macmanus

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2007-1351

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE versions (affected versions not specified) SUSE Linux Enterprise versions (affected versions not specified) X.Org libXfont versions prior to 20070403 freetype versions prior to 2.3.2 Gentoo Linux freetype versions prior to 2.1.10-r3
Description The issue involves multiple vulnerabilities in various packages of openSUSE and SUSE Linux Enterprise operating systems, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, an integer overflow in the bdfReadCharacters function in bdfread.c in X.Org libXfont before 20070403 and freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, resulting in a heap overflow.
Recommendations For openSUSE and SUSE Linux Enterprise, update the affected packages to the latest versions. For X.Org libXfont, update to version 20070403 or later. For freetype, update to version 2.3.2 or later. For Gentoo Linux freetype, update to version 2.1.10-r3 or later. As a temporary workaround, consider restricting access to the vulnerable packages until a patch is available. Avoid using the bdfReadCharacters function in the affected X.Org libXfont and freetype versions until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04594
BDU:2015-04595
BDU:2015-04596
BDU:2015-04597
BDU:2015-04598
BDU:2015-04599
BDU:2015-04600
BDU:2015-04956
BDU:2015-04957
BDU:2015-04958
BDU:2015-04959
BDU:2015-04960
BDU:2015-04961
BDU:2015-09558
CVE-2007-1351
DSA-1294-1
DSA-1454-1
OPENSUSE-SU-2024:10770-1
RHSA-2007:0125
RHSA-2007:0126
RHSA-2007:0132
RHSA-2007:0150
RHSA-2007_0126
RHSA-2007_0132
RHSA-2007_0150

Affected Products

Gentoo Linux
Red Hat
Suse Linux Enterprise
X.Org Libxfont
Freetype
Opensuse