Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| X11r6 | Xfree86_project | 3.3 (including) | 3.3 (including) |
| X11r6 | Xfree86_project | 3.3.2 (including) | 3.3.2 (including) |
| X11r6 | Xfree86_project | 3.3.3 (including) | 3.3.3 (including) |
| X11r6 | Xfree86_project | 3.3.4 (including) | 3.3.4 (including) |
| X11r6 | Xfree86_project | 3.3.5 (including) | 3.3.5 (including) |
| Irix | Sgi | 6.5 (including) | 6.5 (including) |
| Irix | Sgi | 6.5.1 (including) | 6.5.1 (including) |
| Irix | Sgi | 6.5.2 (including) | 6.5.2 (including) |
| Irix | Sgi | 6.5.3 (including) | 6.5.3 (including) |
| Irix | Sgi | 6.5.4 (including) | 6.5.4 (including) |
| Irix | Sgi | 6.5.5 (including) | 6.5.5 (including) |
| Irix | Sgi | 6.5.6 (including) | 6.5.6 (including) |
| Irix | Sgi | 6.5.7 (including) | 6.5.7 (including) |
| Irix | Sgi | 6.5.8 (including) | 6.5.8 (including) |
| Irix | Sgi | 6.5.9 (including) | 6.5.9 (including) |
| Irix | Sgi | 6.5.10 (including) | 6.5.10 (including) |
| Irix | Sgi | 6.5.11 (including) | 6.5.11 (including) |
| Irix | Sgi | 6.5.12 (including) | 6.5.12 (including) |
| Irix | Sgi | 6.5.13 (including) | 6.5.13 (including) |