3.8

CVE-2007-1352

Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.

Data is provided by the National Vulnerability Database (NVD)
MandrakesoftMandrake Multi Network Firewall Version2.0
   MandrakesoftMandrake Linux Version9.1
   MandrakesoftMandrake Linux Version9.1 Editionppc
   MandrakesoftMandrake Linux Version9.2
   MandrakesoftMandrake Linux Version9.2 Editionamd64
   MandrakesoftMandrake Linux Version10.0
   MandrakesoftMandrake Linux Version10.0 Editionamd64
   MandrakesoftMandrake Linux Version2007
   MandrakesoftMandrake Linux Version2007 Editionx86_64
   MandrakesoftMandrake Linux Corporate Server Version3.0
   MandrakesoftMandrake Linux Corporate Server Version3.0 Editionx86_64
   MandrakesoftMandrake Linux Corporate Server Version4.0
   MandrakesoftMandrake Linux Corporate Server Version4.0 Editionx86_64
X.OrgLibxfont Version1.2.2
RedhatEnterprise Linux Version2.1 Editionadvanced_server
RedhatEnterprise Linux Version2.1 Editionadvanced_server_ia64
RedhatEnterprise Linux Version2.1 Editionenterprise_server
RedhatEnterprise Linux Version2.1 Editionenterprise_server_ia64
RedhatEnterprise Linux Version2.1 Editionworkstation
RedhatEnterprise Linux Version2.1 Editionworkstation_ia64
RedhatEnterprise Linux Version3.0 Editionadvanced_server
RedhatEnterprise Linux Version3.0 Editionenterprise_server
RedhatEnterprise Linux Version3.0 Editionworkstation_server
RedhatEnterprise Linux Version4.0 Editionadvanced_server
RedhatEnterprise Linux Version4.0 Editionenterprise_server
RedhatEnterprise Linux Version4.0 Editionworkstation
RedhatEnterprise Linux Desktop Version5.0 Editionclient
RedhatEnterprise Linux Desktop Version5.0 Editionclient_workstation
RedhatFedora Core Versioncore_1.0
RedhatLinux Version9.0 Editioni386
RedhatLinux Advanced Workstation Version2.1 Editionia64
RedhatLinux Advanced Workstation Version2.1 Editionitanium
SlackwareSlackware Linux Version9.0
SlackwareSlackware Linux Version9.1
SlackwareSlackware Linux Versioncurrent
TurbolinuxTurbolinux Desktop Version10.0
UbuntuUbuntu Linux Version4.1 Editionia32
UbuntuUbuntu Linux Version4.1 Editionia64
UbuntuUbuntu Linux Version4.1 Editionppc
UbuntuUbuntu Linux Version5.10 Editionamd64
UbuntuUbuntu Linux Version5.10 Editioni386
UbuntuUbuntu Linux Version5.10 Editionpowerpc
UbuntuUbuntu Linux Version5.10 Editionsparc
UbuntuUbuntu Linux Version6.06_lts Editionamd64
UbuntuUbuntu Linux Version6.06_lts Editioni386
UbuntuUbuntu Linux Version6.06_lts Editionpowerpc
UbuntuUbuntu Linux Version6.06_lts Editionsparc
UbuntuUbuntu Linux Version6.10 Editionamd64
UbuntuUbuntu Linux Version6.10 Editioni386
UbuntuUbuntu Linux Version6.10 Editionpowerpc
UbuntuUbuntu Linux Version6.10 Editionsparc
RpathLinux Version1
OpenbsdOpenbsd Version3.9
OpenbsdOpenbsd Version4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.32% 0.79
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.8 4.4 4.9
AV:A/AC:M/Au:S/C:N/I:P/A:P