CVE-2013-6462: Buffer Overflow
Published Jan 9, 2014
·Updated
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.
Affected Software
23 affected components
X libXfont=1.1.0
X libXfont=1.2.0
X libXfont=1.2.1
X libXfont=1.2.2
X libXfont=1.2.3
X libXfont=1.2.4
X libXfont=1.2.5
X libXfont=1.2.6
X libXfont=1.2.7
X libXfont=1.2.8
X libXfont=1.2.9
X libXfont=1.3.0
X libXfont=1.3.1
X libXfont=1.3.2
X libXfont=1.3.3
X libXfont=1.3.4
X libXfont=1.4.0
X libXfont=1.4.1
X libXfont=1.4.2
X libXfont=1.4.3
X libXfont=1.4.4
X libXfont=1.4.5
X libXfont=1.4.6
Remediation
Event History
Jan 9, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·06:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6462?
CVE-2013-6462 has a high severity as it can lead to a denial of service or potentially allow remote code execution.
2
How do I fix CVE-2013-6462?
To fix CVE-2013-6462, upgrade the X.Org libXfont library to version 1.4.7 or later.
3
What software is affected by CVE-2013-6462?
CVE-2013-6462 affects X.Org libXfont versions 1.1.0 through 1.4.6.
4
What type of vulnerability is CVE-2013-6462?
CVE-2013-6462 is a stack-based buffer overflow vulnerability.
5
Can CVE-2013-6462 be exploited remotely?
Yes, CVE-2013-6462 can be exploited remotely through a crafted BDF font file.