An integer overflow was discovered in the way freetype processes malformed PCF files. It seems that Xorg also contains the same PCF processing code as freetype, there it too is vulnerable this issue. We initally described this issue for freetype in bug 190593. The upstream bug is here: https://bugs.freedesktop.org/show_bug.cgi?id=7535
The upstream patch is attachment 134155 [details]
New packages: xorg-x11-6.8.2-1.EL.13.37
Created attachment 134276 [details] Demo font file
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2006-0634.html