PT-2014-1832 · X.Org Foundation+5 · Libxfont+5

Published

2014-05-13

·

Updated

2018-10-09

·

CVE-2014-0210

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libXfont versions prior to 1.4.8 libXfont versions 1.4.9x prior to 1.4.99.901
Description The issue involves multiple buffer overflows in the libXfont package, allowing remote font servers to execute arbitrary code via crafted xfs protocol replies to various functions, including fs recv conn setup, fs read open font, fs read query info, fs read extent info, fs read glyphs, fs read list, and fs read list info. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely.
Recommendations For libXfont versions prior to 1.4.8, update to version 1.4.8 or later. For libXfont versions 1.4.9x prior to 1.4.99.901, update to version 1.4.99.901 or later. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available. Avoid using the vulnerable libXfont package for remote font server connections until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1649
BDU:2015-06368
BDU:2015-06369
BDU:2015-06370
BDU:2015-06371
BDU:2015-06372
BDU:2015-06373
BDU:2015-06374
BDU:2015-09764
CESA-2014_1870
CVE-2014-0210
DSA-2927-1
MGASA-2014-0278
OPENSUSE-SU-2024:10299-1
RHSA-2014:1870
RHSA-2014:1893
RHSA-2014_1870
RHSA-2014_1893
SUSE-SU-2015:0674-1
USN-2211-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxfont