Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1803

Опубликовано: 17 мар. 2015
Источник: redhat
CVSS2: 1.9

Описание

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.

A NULL pointer dereference flaw was discovered in the way libXfont processed certain Glyph Bitmap Distribution Format (BDF) fonts. A malicious, local user could use this flaw to crash the X.Org server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libXfontAffected
Red Hat Enterprise Linux 6libXfontFixedRHSA-2015:170803.09.2015
Red Hat Enterprise Linux 7libXfontFixedRHSA-2015:170803.09.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-252->CWE-391->CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1203718libXfont: crash on invalid read in bdfReadCharacters

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.

nvd
больше 10 лет назад

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.

debian
больше 10 лет назад

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont b ...

github
больше 3 лет назад

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.

suse-cvrf
больше 10 лет назад

Security update for libXfont

1.9 Low

CVSS2