10
CVSSv2

CVE-2004-0083

Published: 03/03/2004 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 up to and including 4.3.0 allows local users and remote malicious users to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

Vulnerable Product Search on Vulmon Subscribe to Product

xfree86 project x11r6 4.3.0

xfree86 project x11r6 4.1.0

xfree86 project x11r6 4.1.11

xfree86 project x11r6 4.2.1

xfree86 project x11r6 4.1.12

xfree86 project x11r6 4.2.0

openbsd openbsd 3.3

openbsd openbsd 3.4

Vendor Advisories

A number of vulnerabilities have been discovered in XFree86 The corrections are listed below with the identification from the Common Vulnerabilities and Exposures (CVE) project: CAN-2004-0083: Buffer overflow in ReadFontAlias from dirfilec of XFree86 410 through 430 allows local users and remote attackers to execute arbitrary cod ...

Exploits

source: wwwsecurityfocuscom/bid/9636/info It has been reported that the XFree86 X Windows system is prone to a local buffer overflow vulnerability The issue arises from improper bounds checking when parsing the 'fontalias' file Successful exploitation of this issue may allow an attacker to gain root privileges to the affected system ...