CVE-2014-0209: Buffer Overflow
Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0209?
CVE-2014-0209 has a high severity rating due to the potential for local privilege escalation.
How do I fix CVE-2014-0209?
To fix CVE-2014-0209, update the X.Org libXfont to version 1.4.8 or later.
Which versions of X.Org libXfont are affected by CVE-2014-0209?
CVE-2014-0209 affects X.Org libXfont versions before 1.4.8 and 1.4.9x before 1.4.99.901.
Can CVE-2014-0209 be exploited remotely?
No, CVE-2014-0209 requires local access for exploitation.
What systems are affected by CVE-2014-0209?
CVE-2014-0209 primarily affects systems running versions of Ubuntu Linux and other distributions with the vulnerable X.Org libXfont.