CVE-2014-0211: Buffer Overflow
Multiple integer overflows in the (1) fsgetreply, (2) fsallocglyphs, and (3) fsreadextentinfo functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs reply, which triggers a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0211?
CVE-2014-0211 has a high severity rating due to its potential for remote code execution through crafted font server replies.
How do I fix CVE-2014-0211?
To fix CVE-2014-0211, upgrade to libXfont version 1.4.8 or later.
Which software is affected by CVE-2014-0211?
CVE-2014-0211 affects X.Org libXfont versions prior to 1.4.8 and various Ubuntu Linux distributions including versions 10.04 to 14.04.
What types of applications are at risk from CVE-2014-0211?
Applications that utilize X.Org libXfont for font rendering are at risk from CVE-2014-0211.
Can CVE-2014-0211 be exploited remotely?
Yes, CVE-2014-0211 can be exploited remotely via crafted replies from vulnerable font servers.