CVE Vulnerabilities

CVE-2014-0209

Published: May 15, 2014 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.9 IMPORTANT
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.

Affected Software

Name Vendor Start Version End Version
Libxfont X * 1.4.7 (including)
Libxfont X 1.2.3 (including) 1.2.3 (including)
Libxfont X 1.2.4 (including) 1.2.4 (including)
Libxfont X 1.2.5 (including) 1.2.5 (including)
Libxfont X 1.2.6 (including) 1.2.6 (including)
Libxfont X 1.2.7 (including) 1.2.7 (including)
Libxfont X 1.2.8 (including) 1.2.8 (including)
Libxfont X 1.2.9 (including) 1.2.9 (including)
Libxfont X 1.3.0 (including) 1.3.0 (including)
Libxfont X 1.3.1 (including) 1.3.1 (including)
Libxfont X 1.3.2 (including) 1.3.2 (including)
Libxfont X 1.3.3 (including) 1.3.3 (including)
Libxfont X 1.3.4 (including) 1.3.4 (including)
Libxfont X 1.4.0 (including) 1.4.0 (including)
Libxfont X 1.4.1 (including) 1.4.1 (including)
Libxfont X 1.4.2 (including) 1.4.2 (including)
Libxfont X 1.4.3 (including) 1.4.3 (including)
Libxfont X 1.4.4 (including) 1.4.4 (including)
Libxfont X 1.4.5 (including) 1.4.5 (including)
Libxfont X 1.4.6 (including) 1.4.6 (including)
Libxfont X 1.4.99 (including) 1.4.99 (including)
Red Hat Enterprise Linux 5 RedHat libXfont-0:1.2.2-1.0.6.el5_11 *
Red Hat Enterprise Linux 6 RedHat libXfont-0:1.4.5-4.el6_6 *
Red Hat Enterprise Linux 7 RedHat libXfont-0:1.4.7-2.el7_0 *
Libxfont Ubuntu lucid *
Libxfont Ubuntu precise *
Libxfont Ubuntu quantal *
Libxfont Ubuntu saucy *
Libxfont Ubuntu trusty *
Libxfont Ubuntu upstream *

References