CVE Vulnerabilities

CVE-2007-1351

Published: Apr 06, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxUbuntu5.10 (including)5.10 (including)
Ubuntu_linuxUbuntu6.06_lts (including)6.06_lts (including)
Ubuntu_linuxUbuntu6.10 (including)6.10 (including)
Red Hat Enterprise Linux 2.1RedHatXFree86-0:4.1.0-82.EL*
Red Hat Enterprise Linux 3RedHatXFree86-0:4.3.0-120.EL*
Red Hat Enterprise Linux 3RedHatfreetype-0:2.1.4-6.el3*
Red Hat Enterprise Linux 4RedHatxorg-x11-0:6.8.2-1.EL.13.37.7*
Red Hat Enterprise Linux 4RedHatfreetype-0:2.1.9-5.el4*
Red Hat Enterprise Linux 5RedHatlibXfont-0:1.2.2-1.0.2.el5*
Red Hat Enterprise Linux 5RedHatfreetype-0:2.2.1-17.el5*
FreetypeUbuntudapper*
FreetypeUbuntuedgy*
FreetypeUbuntufeisty*
FreetypeUbuntuupstream*
LibxfontUbuntudapper*
LibxfontUbuntudevel*
LibxfontUbuntuedgy*
LibxfontUbuntufeisty*

References