CVE-2014-0210: Buffer Overflow
Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) fsrecvconnsetup, (2) fsreadopenfont, (3) fsreadqueryinfo, (4) fsreadextentinfo, (5) fsreadglyphs, (6) fsreadlist, or (7) fsreadlistinfo function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0210?
CVE-2014-0210 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2014-0210?
To fix CVE-2014-0210, upgrade to libXfont version 1.4.8 or later.
What software is affected by CVE-2014-0210?
CVE-2014-0210 affects X.Org libXfont versions prior to 1.4.8 and multiple specific versions up to 1.4.7.
What type of vulnerability is CVE-2014-0210?
CVE-2014-0210 is a buffer overflow vulnerability.
Can CVE-2014-0210 be exploited without authentication?
Yes, CVE-2014-0210 can be exploited remotely without authentication through crafted xfs protocol replies.