Bug 235265 (CVE-2007-1351, CVE-2007-1352) - CVE-2007-1351 Multiple font integer overflows (CVE-2007-1352)
Summary: CVE-2007-1351 Multiple font integer overflows (CVE-2007-1352)
Alias: CVE-2007-1351, CVE-2007-1352
Product: Security Response
Classification: Other
Component: vulnerability   
(Show other bugs)
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Søren Sandmann Pedersen
QA Contact:
Whiteboard: impact=important,reported=20070322,pu...
Keywords: Security
Depends On:
TreeView+ depends on / blocked
Reported: 2007-04-04 18:55 UTC by Josh Bressers
Modified: 2018-08-15 23:32 UTC (History)
4 users (show)

Fixed In Version: 1.2.8-1
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2007-08-02 17:33:44 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

Description Josh Bressers 2007-04-04 18:55:20 UTC
+++ This bug was initially created as a clone of Bug #234058 +++

+++ This bug was initially created as a clone of Bug #234055 +++

iDEFENSE has reported two font related integer overflows.

CVE-2007-1351 describes an integer overflow in the way X parses a BDF font file.

CVE-2007-1352 describes an integer overflow in thw way X parses a fonts.dir file.

Both of these flaws could allow a local attacker to gain elevated privileges.

-- Additional comment from bressers@redhat.com on 2007-03-26 16:29 EST --
attachment 150950 [details] is the proposed upstream patch

This flaw also affects FC5

Comment 1 Josh Bressers 2007-04-10 20:39:43 UTC
Ping on this flaw, we need to fix this.

Comment 2 Lubomir Kundrak 2007-08-02 12:23:15 UTC
Sandmann: please do push an updated package for FC6

Comment 3 Søren Sandmann Pedersen 2007-08-02 17:33:44 UTC
Was fixed by

* Fri Apr 06 2007 Adam Jackson <ajax@redhat.com> 1.2.8-1
- libXfont 1.2.8.

Note You need to log in before you can comment on or make changes to this bug.