CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
96.0%
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
Vendor | Product | Version | CPE |
---|---|---|---|
xfree86_project | x11r6 | 3.3 | cpe:2.3:a:xfree86_project:x11r6:3.3:*:*:*:*:*:*:* |
xfree86_project | x11r6 | 3.3.2 | cpe:2.3:a:xfree86_project:x11r6:3.3.2:*:*:*:*:*:*:* |
xfree86_project | x11r6 | 3.3.3 | cpe:2.3:a:xfree86_project:x11r6:3.3.3:*:*:*:*:*:*:* |
xfree86_project | x11r6 | 3.3.4 | cpe:2.3:a:xfree86_project:x11r6:3.3.4:*:*:*:*:*:*:* |
xfree86_project | x11r6 | 3.3.5 | cpe:2.3:a:xfree86_project:x11r6:3.3.5:*:*:*:*:*:*:* |
sgi | irix | 6.5 | cpe:2.3:o:sgi:irix:6.5:*:*:*:*:*:*:* |
sgi | irix | 6.5.1 | cpe:2.3:o:sgi:irix:6.5.1:*:*:*:*:*:*:* |
sgi | irix | 6.5.2 | cpe:2.3:o:sgi:irix:6.5.2:*:*:*:*:*:*:* |
sgi | irix | 6.5.3 | cpe:2.3:o:sgi:irix:6.5.3:*:*:*:*:*:*:* |
sgi | irix | 6.5.4 | cpe:2.3:o:sgi:irix:6.5.4:*:*:*:*:*:*:* |
ftp://patches.sgi.com/support/free/security/advisories/20021202-01-I
bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21541
marc.info/?l=bugtraq&m=103825150527843&w=2
sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/48879
www.cert.org/advisories/CA-2002-34.html
www.ciac.org/ciac/bulletins/n-024.shtml
www.iss.net/security_center/static/10375.php
www.kb.cert.org/vuls/id/312313
www.securityfocus.com/advisories/4988
www.securityfocus.com/bid/6241
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A149
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A152
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2816