CVE-2004-0084: Buffer Overflow
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0084?
CVE-2004-0084 has a high severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2004-0084?
To fix CVE-2004-0084, update the XFree86 X Server to a version beyond 4.3.0 where the vulnerability has been addressed.
Who is affected by CVE-2004-0084?
Users of XFree86 versions 4.1.0 to 4.3.0, including OpenBSD 3.3 and 3.4, are potentially affected by CVE-2004-0084.
What causes the vulnerability in CVE-2004-0084?
The vulnerability in CVE-2004-0084 is caused by a buffer overflow in the ReadFontAlias function when processing a malformed font alias file.
Can CVE-2004-0084 be exploited remotely?
Yes, CVE-2004-0084 can be exploited remotely by authenticated users through specially crafted font alias entries.