Back

HIGH

libXfont: unvalidated length fields when parsing xfs protocol replies

Published May 15, 2014

Description

Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, (4) fs_read_extent_info, (5) fs_read_glyphs, (6) fs_read_list, or (7) fs_read_list_info function.

Affected products

Remediation

No remediation recorded yet.

References (18)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published May 15, 2014
Updated Aug 6, 2024
Reserved Dec 3, 2013

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 13, 2014
Bugzilla 1096597

ENISA EUVD

Assigner redhat
Published May 15, 2014
Updated Aug 6, 2024

GitHub

No data