First published: Fri Apr 06 2007(Updated: )
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
X.Org LibXfont | =1.2.2 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Enterprise Linux | =4.0 | |
redhat enterprise Linux desktop | =3.0 | |
Red Hat Linux Advanced Workstation | =2.1 | |
Red Hat Enterprise Linux | =4.0 | |
Red Hat Enterprise Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Linux Advanced Workstation | =2.1 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Fedora Core | =core_1.0 | |
Red Hat Linux | =9.0 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =5.0 | |
Red Hat Enterprise Linux | =4.0 | |
Red Hat Enterprise Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Enterprise Linux | =2.1 | |
redhat enterprise Linux desktop | =4.0 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Enterprise Linux | =3.0 | |
Slackware Linux | =9.0 | |
Slackware Linux | =9.1 | |
Slackware Linux | =current | |
TurboLinux Desktop | =10.0 | |
Ubuntu | =6.10 | |
Ubuntu | =4.1 | |
Ubuntu | =5.10 | |
Ubuntu | =6.06_lts | |
Ubuntu | =4.1 | |
Ubuntu | =5.10 | |
Ubuntu | =6.10 | |
Ubuntu | =5.10 | |
Ubuntu | =5.10 | |
Ubuntu | =6.06_lts | |
Ubuntu | =6.10 | |
Ubuntu | =6.06_lts | |
Ubuntu | =6.06_lts | |
Ubuntu | =4.1 | |
Ubuntu | =6.10 | |
rPath Linux | =1 | |
OpenBSD | =3.9 | |
OpenBSD | =4.0 | |
Mandrake Linux | =9.1 | |
Mandrake Linux | =9.1 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =2007 | |
Mandrake Linux | =2007 | |
Mandriva Linux Corporate Server | =3.0 | |
Mandriva Linux Corporate Server | =3.0 | |
Mandriva Linux Corporate Server | =4.0 | |
Mandriva Linux Corporate Server | =4.0 | |
Mandrakesoft Mandrake Multi Network Firewall | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1352 has been assigned a moderate severity rating due to the potential for remote authenticated users to execute arbitrary code.
To mitigate CVE-2007-1352, users should update to the latest version of X.Org libXfont or apply patches provided by their Linux distribution.
CVE-2007-1352 affects users of X.Org libXfont versions prior to 20070403 and various Red Hat Enterprise Linux and Ubuntu versions.
An attacker can exploit CVE-2007-1352 by creating a malicious fonts.dir file, leading to a heap overflow and potential arbitrary code execution.
Vulnerable versions include X.Org libXfont versions below 1.2.2 and specific versions of Red Hat Enterprise Linux and Ubuntu.