7.5

CVE-2014-0210

Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, (4) fs_read_extent_info, (5) fs_read_glyphs, (6) fs_read_list, or (7) fs_read_list_info function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
X ≫ Libxfont Version <= 1.4.7
X ≫ Libxfont Version 1.2.3
X ≫ Libxfont Version 1.2.4
X ≫ Libxfont Version 1.2.5
X ≫ Libxfont Version 1.2.6
X ≫ Libxfont Version 1.2.7
X ≫ Libxfont Version 1.2.8
X ≫ Libxfont Version 1.2.9
X ≫ Libxfont Version 1.3.0
X ≫ Libxfont Version 1.3.1
X ≫ Libxfont Version 1.3.2
X ≫ Libxfont Version 1.3.3
X ≫ Libxfont Version 1.3.4
X ≫ Libxfont Version 1.4.0
X ≫ Libxfont Version 1.4.1
X ≫ Libxfont Version 1.4.2
X ≫ Libxfont Version 1.4.3
X ≫ Libxfont Version 1.4.4
X ≫ Libxfont Version 1.4.5
X ≫ Libxfont Version 1.4.6
X ≫ Libxfont Version 1.4.99
Canonical ≫ Ubuntu Linux Version 10.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.10
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.36% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://seclists.org/fulldisclosure/2014/Dec/23
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
http://www.securityfocus.com/archive/1/534161/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
http://advisories.mageia.org/MGASA-2014-0278.html
http://lists.opensuse.org/opensuse-updates/2014-05/msg00073.html
http://lists.x.org/archives/xorg-announce/2014-May/002431.html
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2014-1893.html
http://secunia.com/advisories/59154
http://www.debian.org/security/2014/dsa-2927
http://www.mandriva.com/security/advisories?name=MDVSA-2015:145
http://www.securityfocus.com/bid/67382
http://www.ubuntu.com/usn/USN-2211-1