Lucene search

K
osvGoogleOSV:DSA-360
HistoryAug 01, 2003 - 12:00 a.m.

xfstt - several vulnerabilities

2003-08-0100:00:00
Google
osv.dev
9

0.013 Low

EPSS

Percentile

85.7%

xfstt, a TrueType font server for the X window system was found to
contain two classes of vulnerabilities:


CAN-2003-0581
: a remote attacker could send requests crafted to
trigger any of several buffer overruns, causing a denial of service or
possibly executing arbitrary code on the server with the privileges
of the “nobody” user.


CAN-2003-0625
: certain invalid data sent during the connection
handshake could allow a remote attacker to read certain regions of
memory belonging to the xfstt process. This information could be
used for fingerprinting, or to aid in exploitation of a different
vulnerability.

For the current stable distribution (woody) these problems have been
fixed in version 1.2.1-3.

For the unstable distribution (sid), CAN-2003-0581 is fixed in xfstt
1.5-1, and CAN-2003-0625 will be fixed soon.

We recommend that you update your xfstt package.

0.013 Low

EPSS

Percentile

85.7%