Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1804

Опубликовано: 17 мар. 2015
Источник: redhat
CVSS2: 6.9

Описание

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file.

An integer truncation flaw was discovered in the way libXfont processed certain Glyph Bitmap Distribution Format (BDF) fonts. A malicious, local user could use this flaw to crash the X.Org server or, potentially, execute arbitrary code with the privileges of the X.Org server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libXfontAffected
Red Hat Enterprise Linux 6libXfontFixedRHSA-2015:170803.09.2015
Red Hat Enterprise Linux 7libXfontFixedRHSA-2015:170803.09.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-704->CWE-681->CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=1203719libXfont: out-of-bounds memory access in bdfReadCharacters

6.9 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file.

nvd
больше 10 лет назад

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file.

debian
больше 10 лет назад

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont b ...

suse-cvrf
больше 9 лет назад

Security update for libXfont

suse-cvrf
больше 9 лет назад

Recommended update for libXfont

6.9 Medium

CVSS2