PT-2007-7524 · X.Org+2 · X.Org Libxfont+3

Greg Macmanus

·

Published

1970-01-01

·

Updated

2018-10-16

·

CVE-2007-1352

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE versions (affected versions not specified) SUSE Linux Enterprise versions (affected versions not specified) X.Org libXfont versions prior to 20070403
Description The issue involves multiple vulnerabilities in various packages of openSUSE and SUSE Linux Enterprise operating systems, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, an integer overflow in the FontFileInitTable function in X.Org libXfont allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, resulting in a heap overflow.
Recommendations For openSUSE, update to a version that includes the fix for the vulnerabilities. For SUSE Linux Enterprise, update to a version that includes the fix for the vulnerabilities. For X.Org libXfont, update to version 20070403 or later. As a temporary workaround, consider restricting access to the vulnerable packages until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04594
BDU:2015-04595
BDU:2015-04596
BDU:2015-04597
BDU:2015-04598
BDU:2015-04599
BDU:2015-04600
BDU:2015-04956
BDU:2015-04957
BDU:2015-04958
BDU:2015-04959
BDU:2015-04960
BDU:2015-04961
CVE-2007-1352
DSA-1294-1
RHSA-2007:0125
RHSA-2007:0126
RHSA-2007:0132
RHSA-2007_0126
RHSA-2007_0132

Affected Products

Red Hat
Suse Linux Enterprise
X.Org Libxfont
Opensuse