Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-13720

Опубликовано: 04 окт. 2017
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libXfontWill not fix
Red Hat Enterprise Linux 6libXfontWill not fix
Red Hat Enterprise Linux 7libXfontWill not fix
Red Hat Enterprise Linux 7libXfont2Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1500690libXfont: Insufficient input validation in fontdir.c

EPSS

Процентиль: 37%
0.00442
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 9 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

CVSS3: 7.1
nvd
почти 9 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

CVSS3: 7.1
debian
почти 9 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through ...

CVSS3: 7.1
github
больше 4 лет назад

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.

suse-cvrf
больше 8 лет назад

Security update for libXfont

EPSS

Процентиль: 37%
0.00442
Низкий

4.4 Medium

CVSS3