Lucene search

K
f5F5F5:K17444
HistoryOct 16, 2015 - 12:00 a.m.

K17444 : libXfont vulnerabilities CVE-2015-1802, CVE-2015-1803, and CVE-2015-1804

2015-10-1600:00:00
my.f5.com
15

5.2 Medium

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.9%

Security Advisory Description

The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a (1) negative or (2) large property count in a BDF font file.

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file.

Impact

A local user can exploit this issue to potentially execute arbitrary code with the privileges of the X.Org server.