Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2014-05-15 07:55
Updated : 2018-10-09 12:38
NVD link : CVE-2014-0209
Mitre link : CVE-2014-0209
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
canonical
- ubuntu_linux
x
- libxfont