Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-13722

Опубликовано: 11 окт. 2017
Источник: debian
EPSS Низкий

Описание

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxfontfixed1:2.0.1-4package
libxfont1removedpackage

Примечания

  • Fixed by: https://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=672bb944311392e2415b39c0d63b1e1902905bcd

  • libxfont1 is only used by xfonts-utils, no security impact

EPSS

Процентиль: 28%
0.001
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 8 лет назад

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server.

CVSS3: 4.4
redhat
больше 8 лет назад

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server.

CVSS3: 7.1
nvd
больше 8 лет назад

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server.

CVSS3: 7.1
github
больше 3 лет назад

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server.

suse-cvrf
около 8 лет назад

Security update for libXfont

EPSS

Процентиль: 28%
0.001
Низкий