5.5

CVE-2017-16611

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.04
Canonical ≫ Ubuntu Linux Version 17.10
X ≫ Libxfont Version >= 1.0.0 < 1.5.4
X ≫ Libxfont Version >= 2.0.0 < 2.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.334
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

http://security.cucumberlinux.com/security/details.php?id=155
Third Party Advisory
http://www.openwall.com/lists/oss-security/2017/11/28/7
Patch
Third Party Advisory
Mailing List
http://www.ubuntu.com/usn/USN-3500-1
Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1050459
VDB Entry
Issue Tracking
Tool Signature
https://lists.debian.org/debian-lts-announce/2022/01/msg00028.html
Third Party Advisory
Mailing List
Issue Tracking
https://marc.info/?l=freedesktop-xorg-announce&m=151188044218304&w=2
Patch
Third Party Advisory
https://marc.info/?l=freedesktop-xorg-announce&m=151188049718337&w=2
Patch
Third Party Advisory
https://security.gentoo.org/glsa/201801-10
Third Party Advisory