Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2014-0018

Опубликовано: 10 янв. 2014
Источник: oracle-oval
Платформа: Oracle Linux 5
Платформа: Oracle Linux 6

Описание

ELSA-2014-0018: libxfont security update (IMPORTANT)

[1.4.5-3]

  • cve-2013-6462.patch: sscanf overflow (bug 1049684)
  • sscanf-hardening.patch: Some other sscanf hardening fixes (1049684)

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

libXfont

1.2.2-1.0.5.el5_10

libXfont-devel

1.2.2-1.0.5.el5_10

Oracle Linux x86_64

libXfont

1.2.2-1.0.5.el5_10

libXfont-devel

1.2.2-1.0.5.el5_10

Oracle Linux i386

libXfont

1.2.2-1.0.5.el5_10

libXfont-devel

1.2.2-1.0.5.el5_10

Oracle Linux 6

Oracle Linux x86_64

libXfont

1.4.5-3.el6_5

libXfont-devel

1.4.5-3.el6_5

Oracle Linux i686

libXfont

1.4.5-3.el6_5

libXfont-devel

1.4.5-3.el6_5

Связанные CVE

Связанные уязвимости

ubuntu
больше 11 лет назад

Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.

redhat
больше 11 лет назад

Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.

nvd
больше 11 лет назад

Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.

debian
больше 11 лет назад

Stack-based buffer overflow in the bdfReadCharacters function in bitma ...

github
больше 3 лет назад

Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.