First published: Thu Jan 09 2014(Updated: )
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Libxfont | =1.1.0 | |
Red Hat Libxfont | =1.2.0 | |
Red Hat Libxfont | =1.2.1 | |
Red Hat Libxfont | =1.2.2 | |
Red Hat Libxfont | =1.2.3 | |
Red Hat Libxfont | =1.2.4 | |
Red Hat Libxfont | =1.2.5 | |
Red Hat Libxfont | =1.2.6 | |
Red Hat Libxfont | =1.2.7 | |
Red Hat Libxfont | =1.2.8 | |
Red Hat Libxfont | =1.2.9 | |
Red Hat Libxfont | =1.3.0 | |
Red Hat Libxfont | =1.3.1 | |
Red Hat Libxfont | =1.3.2 | |
Red Hat Libxfont | =1.3.3 | |
Red Hat Libxfont | =1.3.4 | |
Red Hat Libxfont | =1.4.0 | |
Red Hat Libxfont | =1.4.1 | |
Red Hat Libxfont | =1.4.2 | |
Red Hat Libxfont | =1.4.3 | |
Red Hat Libxfont | =1.4.4 | |
Red Hat Libxfont | =1.4.5 | |
Red Hat Libxfont | =1.4.6 |
http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=4d024ac10f964f6bd372ae0dd14f02772a6e5f63
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6462 has a high severity as it can lead to a denial of service or potentially allow remote code execution.
To fix CVE-2013-6462, upgrade the X.Org libXfont library to version 1.4.7 or later.
CVE-2013-6462 affects X.Org libXfont versions 1.1.0 through 1.4.6.
CVE-2013-6462 is a stack-based buffer overflow vulnerability.
Yes, CVE-2013-6462 can be exploited remotely through a crafted BDF font file.