Bug 235265 (CVE-2007-1351, CVE-2007-1352) - CVE-2007-1351 Multiple font integer overflows (CVE-2007-1352)
Summary: CVE-2007-1351 Multiple font integer overflows (CVE-2007-1352)
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2007-1351, CVE-2007-1352
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
Assignee: Søren Sandmann Pedersen
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-04-04 18:55 UTC by Josh Bressers
Modified: 2021-11-08 15:44 UTC (History)
4 users (show)

Fixed In Version: 1.2.8-1
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-08-02 17:33:44 UTC
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2007-04-04 18:55:20 UTC
+++ This bug was initially created as a clone of Bug #234058 +++

+++ This bug was initially created as a clone of Bug #234055 +++

iDEFENSE has reported two font related integer overflows.

CVE-2007-1351 describes an integer overflow in the way X parses a BDF font file.

CVE-2007-1352 describes an integer overflow in thw way X parses a fonts.dir file.

Both of these flaws could allow a local attacker to gain elevated privileges.

-- Additional comment from bressers on 2007-03-26 16:29 EST --
attachment 150950 [details] is the proposed upstream patch



This flaw also affects FC5

Comment 1 Josh Bressers 2007-04-10 20:39:43 UTC
Ping on this flaw, we need to fix this.

Comment 2 Lubomir Kundrak 2007-08-02 12:23:15 UTC
Sandmann: please do push an updated package for FC6

Comment 3 Søren Sandmann Pedersen 2007-08-02 17:33:44 UTC
Was fixed by

* Fri Apr 06 2007 Adam Jackson <ajax> 1.2.8-1
- libXfont 1.2.8.




Note You need to log in before you can comment on or make changes to this bug.