Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2014-05-15 14:55
Updated : 2025-04-12 10:46
NVD link : CVE-2014-0209
Mitre link : CVE-2014-0209
CVE.ORG link : CVE-2014-0209
JSON object : View
Products Affected
x
- libxfont
canonical
- ubuntu_linux
CWE
CWE-189
Numeric Errors