HIGH
libXfont: stack-based buffer overflow flaw when parsing Glyph Bitmap Distribution Format (BDF) fonts
Published Jan 9, 2014
9.3
HIGHCVSS 2.0
EPSS 10.25%
Description
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.
Affected products
No data.
OR
- 1.1.0
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.2.9
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
- 1.4.5
- 1.4.6
No data.
Red Hat Enterprise Linux 5
libXfont-0:1.2.2-1.0.5.el5_10
Fixed · RHSA-2014:0018
Red Hat Enterprise Linux 6
libXfont-0:1.4.5-3.el6_5
Fixed · RHSA-2014:0018
Red Hat Enterprise Linux 7
libXfont
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libXfont-0:1.2.2-1.0.5.el5_10 | Fixed | RHSA-2014:0018 |
| Red Hat Enterprise Linux 6 | libXfont-0:1.4.5-3.el6_5 | Fixed | RHSA-2014:0018 |
| Red Hat Enterprise Linux 7 | libXfont | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (21)
- http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=4d024ac10f964f6bd372ae0dd14f02772a6e5f63 x_refsource_CONFIRMExploitPatch
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00050.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00052.html vendor-advisoryx_refsource_SUSE
- http://lists.x.org/archives/xorg-announce/2014-January/002389.html mailing-listx_refsource_MLISTVendor Advisory
- http://osvdb.org/101842 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2014-0018.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/oss-sec/2014/q1/33 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/56240 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/56336 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/56357 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/56371 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-2838 vendor-advisoryx_refsource_DEBIAN
- http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/64694 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2078-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-6462 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1048044 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-6266 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90123 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2013-6462
- https://www.cve.org/CVERecord?id=CVE-2013-6462
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 9, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
Link CVE-2013-6462
CISA Vulnrichment
No data
GitHub
No data