CVE Vulnerabilities

CVE-2014-0209

Published: May 15, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.9 IMPORTANT
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.

Affected Software

NameVendorStart VersionEnd Version
LibxfontX*1.4.7 (including)
LibxfontX1.2.3 (including)1.2.3 (including)
LibxfontX1.2.4 (including)1.2.4 (including)
LibxfontX1.2.5 (including)1.2.5 (including)
LibxfontX1.2.6 (including)1.2.6 (including)
LibxfontX1.2.7 (including)1.2.7 (including)
LibxfontX1.2.8 (including)1.2.8 (including)
LibxfontX1.2.9 (including)1.2.9 (including)
LibxfontX1.3.0 (including)1.3.0 (including)
LibxfontX1.3.1 (including)1.3.1 (including)
LibxfontX1.3.2 (including)1.3.2 (including)
LibxfontX1.3.3 (including)1.3.3 (including)
LibxfontX1.3.4 (including)1.3.4 (including)
LibxfontX1.4.0 (including)1.4.0 (including)
LibxfontX1.4.1 (including)1.4.1 (including)
LibxfontX1.4.2 (including)1.4.2 (including)
LibxfontX1.4.3 (including)1.4.3 (including)
LibxfontX1.4.4 (including)1.4.4 (including)
LibxfontX1.4.5 (including)1.4.5 (including)
LibxfontX1.4.6 (including)1.4.6 (including)
LibxfontX1.4.99 (including)1.4.99 (including)
Red Hat Enterprise Linux 5RedHatlibXfont-0:1.2.2-1.0.6.el5_11*
Red Hat Enterprise Linux 6RedHatlibXfont-0:1.4.5-4.el6_6*
Red Hat Enterprise Linux 7RedHatlibXfont-0:1.4.7-2.el7_0*
LibxfontUbuntuesm-infra-legacy/trusty*
LibxfontUbuntulucid*
LibxfontUbuntuprecise*
LibxfontUbuntuquantal*
LibxfontUbuntusaucy*
LibxfontUbuntutrusty*
LibxfontUbuntutrusty/esm*
LibxfontUbuntuupstream*

References