Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24677
HistoryApr 10, 2020 - 1:01 a.m.

Arbitrary Code Execution

2020-04-1001:01:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.013 Low

EPSS

Percentile

86.1%

libxfont is vulnerable to arbitrary code execution. The vulnerability exists as a buffer overflow flaw was found in the way the libXfont library, used by the X.Org server, handled malformed font files compressed using UNIX compress. A malicious, local user could exploit this issue to potentially execute arbitrary code with the privileges of the X.Org server.

References