Lucene search

K
gentooGentoo FoundationGLSA-201801-10
HistoryJan 08, 2018 - 12:00 a.m.

LibXfont, LibXfont2: Arbitrary file access

2018-01-0800:00:00
Gentoo Foundation
security.gentoo.org
15

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

Background

X.Org Xfont library.

Description

It was discovered that libXfont incorrectly followed symlinks when opening font files.

Impact

A local unprivileged user could use this flaw to cause the X server to access arbitrary files, including special device files.

Workaround

There is no known workaround at this time.

Resolution

All LibXfont users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=x11-libs/libXfont-1.5.4"

All LibXfont2 users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=x11-libs/libXfont2-2.0.3"
OSVersionArchitecturePackageVersionFilename
Gentooanyallx11-libs/libxfont< 1.5.4UNKNOWN
Gentooanyallx11-libs/libxfont2< 2.0.3UNKNOWN

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%