PT-2018-10071 · Gnome+4 · Libgxps+4

Chenyuan

·

Published

2018-05-04

·

Updated

2020-06-19

·

CVE-2018-10733

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libgxps versions prior to 0.3.1
Description The issue is related to a heap-based buffer over-read in the ft font face hash function of gxps-fonts.c. This can be triggered by a crafted input, potentially leading to a remote denial of service attack.
Recommendations For versions prior to 0.3.1, update to version 0.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ft font face hash function until a patch is available.

Exploit

Fix

DoS

XSS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1007
BDU:2019-04345
CESA-2018_3140
CVE-2018-10733
MGASA-2019-0003
OPENSUSE-SU-2019:1120-1
OPENSUSE-SU-2019_1120-1
RHSA-2018:3140
RHSA-2018_3140
SUSE-SU-2019:0720-1
SUSE-SU-2019_0720-1
SUSE-SU-2020:1687-1
SUSE-SU-2020_1687-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Libgxps