CVE-2004-0106: High severity Xfree86 Project X11r6 vulnerability
Published Feb 16, 2004
·Updated
Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.
Affected Software
9 affected components
Xfree86 Project X11r6=4.1.0
Xfree86 Project X11r6=4.3.0
Xfree86 Project X11r6=4.2.1
Xfree86 Project X11r6=4.2.0
Xfree86 Project X11r6=4.1.12
Xfree86 Project X11r6=4.2.1
Xfree86 Project X11r6=4.1.11
OpenBSD OpenBSD=3.3
OpenBSD OpenBSD=3.4
Remediation
Patch Available
Patch Available
Event History
Feb 16, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0106?
CVE-2004-0106 is classified as a high severity vulnerability due to the potential for unauthenticated remote code execution.
2
How do I fix CVE-2004-0106?
To fix CVE-2004-0106, upgrade XFree86 to a version that is not vulnerable, such as 4.4.0 or later.
3
Which versions of XFree86 are affected by CVE-2004-0106?
CVE-2004-0106 affects XFree86 versions 4.1.0 through 4.3.0.
4
What types of attacks are enabled by CVE-2004-0106?
CVE-2004-0106 may allow attackers to execute arbitrary code through malicious font files.
5
Is CVE-2004-0106 related to CVE-2004-0083 and CVE-2004-0084?
CVE-2004-0106 describes a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084, although they all impact XFree86.