PT-2014-1831 · X.Org Foundation+5 · Libxfont+5

Published

2014-05-13

·

Updated

2018-10-09

·

CVE-2014-0209

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libXfont versions prior to 1.4.8
Description The issue is related to multiple integer overflows in the FontFileAddEntry and lexAlias functions, which might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, triggering a heap-based buffer overflow. This is related to metadata. The exploitation of these vulnerabilities can lead to a violation of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For libXfont versions prior to 1.4.8, update to version 1.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the font path to minimize the risk of exploitation. Avoid using large fonts.dir or fonts.alias files in the font path until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1649
BDU:2015-06368
BDU:2015-06369
BDU:2015-06370
BDU:2015-06371
BDU:2015-06372
BDU:2015-06373
BDU:2015-06374
BDU:2015-09764
CESA-2014_1870
CVE-2014-0209
DSA-2927-1
MGASA-2014-0278
OPENSUSE-SU-2024:10299-1
RHSA-2014:1870
RHSA-2014:1893
RHSA-2014_1870
RHSA-2014_1893
SUSE-SU-2014_0774-1
SUSE-SU-2015:0674-1
USN-2211-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxfont