Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Information
                Published : 2014-05-15 07:55
Updated : 2018-10-09 12:38
NVD link : CVE-2014-0209
Mitre link : CVE-2014-0209
JSON object : View
CWE
                
                    
                        
                        CWE-189
                        
            Numeric Errors
Products Affected
                canonical
- ubuntu_linux
x
- libxfont


