7.5
CVSSv2

CVE-2014-0211

Published: 15/05/2014 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont prior to 1.4.8 and 1.4.9x prior to 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs reply, which triggers a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 13.10

canonical ubuntu linux 14.04

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

canonical ubuntu linux 12.10

x libxfont 1.2.8

x libxfont 1.2.9

x libxfont 1.4.1

x libxfont 1.4.2

x libxfont 1.2.3

x libxfont 1.2.4

x libxfont 1.2.5

x libxfont 1.3.2

x libxfont 1.3.3

x libxfont 1.4.5

x libxfont 1.4.6

x libxfont 1.2.6

x libxfont 1.2.7

x libxfont 1.3.4

x libxfont 1.4.0

x libxfont

x libxfont 1.4.99

x libxfont 1.3.0

x libxfont 1.3.1

x libxfont 1.4.3

x libxfont 1.4.4

Vendor Advisories

Several security issues were fixed in libXfont ...
Ilja van Sprundel of IOActive discovered several security issues in the XOrg libXfont library, which may allow a local, authenticated user to attempt to raise privileges; or a remote attacker who can control the font server to attempt to execute code with the privileges of the X server CVE-2014-0209 Integer overflow of allocations in font me ...
Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in XOrg libXfont before 148 and 149x before 1499901 allow remote font servers to execute arbitrary code via a crafted xfs reply, which triggers a buffer overflow Multiple buffer overflows in XOrg libXfont before 148 and 149x ...
Multiple out-of-bounds write flaws were found in the way libXfont parsed replies received from an Xorg font server A malicious Xorg server could cause an X client to crash or, possibly, execute arbitrary code with the privileges of the XOrg server ...