[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-1352Date: (C)2007-04-05   (M)2023-12-22


Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.8
Exploit Score: 4.4
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1017857
SUNALERT-102886
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=502
http://www.securityfocus.com/archive/1/464686/100/0/threaded
http://www.securityfocus.com/archive/1/464816/100/0/threaded
BID-23283
BID-23300
SECUNIA-24741
SECUNIA-24745
SECUNIA-24756
SECUNIA-24758
SECUNIA-24765
SECUNIA-24770
SECUNIA-24771
SECUNIA-24772
SECUNIA-24791
SECUNIA-25004
SECUNIA-25006
SECUNIA-25195
SECUNIA-25216
SECUNIA-25305
SECUNIA-33937
ADV-2007-1217
ADV-2007-1548
APPLE-SA-2007-11-14
APPLE-SA-2009-02-12
DSA-1294
GLSA-200705-10
MDKSA-2007:079
MDKSA-2007:080
RHSA-2007:0125
RHSA-2007:0126
RHSA-2007:0132
SUSE-SA:2007:027
USN-448-1
http://www.openbsd.org/errata39.html#021_xorg
http://www.openbsd.org/errata40.html#011_xorg
http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html
http://issues.foresightlinux.org/browse/FL-223
http://support.apple.com/kb/HT3438
http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm
https://issues.rpath.com/browse/RPL-1213
oval:org.mitre.oval:def:10523
oval:org.mitre.oval:def:13243
xorg-fontsdir-bo(33419)

CPE    13
cpe:/o:mandrakesoft:mandrake_linux:9.1
cpe:/o:openbsd:openbsd:4.0
cpe:/a:mandrakesoft:mandrake_multi_network_firewall:2.0
cpe:/o:mandrakesoft:mandrake_linux:2007
...

© SecPod Technologies