Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-13720

Опубликовано: 04 окт. 2017
Источник: redhat
CVSS3: 4.4

Описание

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libXfontWill not fix
Red Hat Enterprise Linux 6libXfontWill not fix
Red Hat Enterprise Linux 7libXfontWill not fix
Red Hat Enterprise Linux 7libXfont2Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1500690libXfont: Insufficient input validation in fontdir.c

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 8 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

CVSS3: 7.1
nvd
больше 8 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

CVSS3: 7.1
debian
больше 8 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through ...

CVSS3: 7.1
github
больше 3 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

suse-cvrf
около 8 лет назад

Security update for libXfont

4.4 Medium

CVSS3