8.5

CVE-2007-1351

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.

Data is provided by the National Vulnerability Database (NVD)
UbuntuUbuntu Linux Version5.10 Editionamd64
UbuntuUbuntu Linux Version5.10 Editioni386
UbuntuUbuntu Linux Version5.10 Editionpowerpc
UbuntuUbuntu Linux Version5.10 Editionsparc
UbuntuUbuntu Linux Version6.06_lts Editionamd64
UbuntuUbuntu Linux Version6.06_lts Editioni386
UbuntuUbuntu Linux Version6.06_lts Editionpowerpc
UbuntuUbuntu Linux Version6.06_lts Editionsparc
UbuntuUbuntu Linux Version6.10 Editionamd64
UbuntuUbuntu Linux Version6.10 Editioni386
UbuntuUbuntu Linux Version6.10 Editionpowerpc
UbuntuUbuntu Linux Version6.10 Editionsparc
X.OrgLibxfont Version1.2.2
Xfree86 ProjectX11r6 Version4.3.0
Xfree86 ProjectX11r6 Version4.3.0.1
Xfree86 ProjectX11r6 Version4.3.0.2
RpathRpath Linux Version1
RedhatEnterprise Linux Version2.1 Editionadvanced_server
RedhatEnterprise Linux Version2.1 Editionadvanced_server_ia64
RedhatEnterprise Linux Version2.1 Editionenterprise_server
RedhatEnterprise Linux Version2.1 Editionenterprise_server_ia64
RedhatEnterprise Linux Version2.1 Editionworkstation
RedhatEnterprise Linux Version2.1 Editionworkstation_ia64
RedhatEnterprise Linux Version3.0 Editionadvanced_servers
RedhatEnterprise Linux Version3.0 Editionenterprise_server
RedhatEnterprise Linux Version3.0 Editionworkstation
RedhatEnterprise Linux Version4.0 Editionadvanced_server
RedhatEnterprise Linux Version4.0 Editionenterprise_server
RedhatEnterprise Linux Version4.0 Editionworkstation
RedhatEnterprise Linux Version5.0 Editiondesktop
RedhatEnterprise Linux Version5.0 Editiondesktop_workstation
RedhatEnterprise Linux Version5.0 Editionserver
RedhatLinux Advanced Workstation Version2.1 Editionia64
RedhatLinux Advanced Workstation Version2.1 Editionitanium
OpenbsdOpenbsd Version3.9
OpenbsdOpenbsd Version4.0
MandrakesoftMandrake Multi Network Firewall Version2.0
   MandrakesoftMandrake Linux Version2007
   MandrakesoftMandrake Linux Version2007 Editionx86_64
   MandrakesoftMandrake Linux Corporate Server Version3.0
   MandrakesoftMandrake Linux Corporate Server Version3.0 Editionx86_64
   MandrakesoftMandrake Linux Corporate Server Version4.0
   MandrakesoftMandrake Linux Corporate Server Version4.0 Editionx86_64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 7.49% 0.909
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C