Vulnerability Description
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu | Ubuntu Linux | 5.10 |
| X.Org | Libxfont | 1.2.2 |
| Xfree86 Project | X11R6 | 4.3.0 |
| Rpath | Rpath Linux | 1 |
| Redhat | Enterprise Linux | 2.1 |
| Redhat | Enterprise Linux Desktop | 3.0 |
| Redhat | Linux Advanced Workstation | 2.1 |
| Openbsd | Openbsd | 3.9 |
| Mandrakesoft | Mandrake Linux | 2007 |
| Mandrakesoft | Mandrake Linux Corporate Server | 3.0 |
| Mandrakesoft | Mandrake Multi Network Firewall | 2.0 |
Related Weaknesses (CWE)
References
- http://issues.foresightlinux.org/browse/FL-223
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=501Patch
- http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html
- http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html
- http://rhn.redhat.com/errata/RHSA-2007-0125.html
- http://secunia.com/advisories/24741Vendor Advisory
- http://secunia.com/advisories/24745
- http://secunia.com/advisories/24756
- http://secunia.com/advisories/24758
- http://secunia.com/advisories/24765
- http://secunia.com/advisories/24768
- http://secunia.com/advisories/24770Vendor Advisory
- http://secunia.com/advisories/24771
- http://secunia.com/advisories/24772
FAQ
What is CVE-2007-1351?
CVE-2007-1351 is a vulnerability with a CVSS score of 8.5 (HIGH). Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via...
How severe is CVE-2007-1351?
CVE-2007-1351 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1351?
Check the references section above for vendor advisories and patch information. Affected products include: Ubuntu Ubuntu Linux, X.Org Libxfont, Xfree86 Project X11R6, Rpath Rpath Linux, Redhat Enterprise Linux.