Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7981
HistoryDec 06, 2018 - 1:09 a.m.

Denial Of Service (DoS)

2018-12-0601:09:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

26.7%

libXfont.so is vulnerable to denial of service (DoS) attack. The PatternMatch function in fontfile/fontdir.c does not handle the case when a pattern contains the ? character, skipping characters characters such as the NULL character or \0 in the string and eventually crashing when invalid memory is accessed during pattern matching.

CPENameOperatorVersion
libxfont.soeq1.4.1