CVE-2008-0006
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.11% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- sun/solaris libfont · sun/solaris libxfont · x.org/xserver
- Source
- secalert@redhat.com
References
- http://bugs.gentoo.org/show_bug.cgi?id=204362
- http://docs.info.apple.com/article.html?artnum=307562
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321
- http://jvn.jp/en/jp/JVN88935101/index.html
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001043.html
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
- http://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlPatch
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
- http://secunia.com/advisories/28273Vendor Advisory
- http://secunia.com/advisories/28500Vendor Advisory
- http://secunia.com/advisories/28532Vendor Advisory
- http://secunia.com/advisories/28535Vendor Advisory
- http://secunia.com/advisories/28536Vendor Advisory
- http://secunia.com/advisories/28540Vendor Advisory
- http://secunia.com/advisories/28542Vendor Advisory
- http://secunia.com/advisories/28544Vendor Advisory
- http://secunia.com/advisories/28550Vendor Advisory
- http://secunia.com/advisories/28571Vendor Advisory
- http://secunia.com/advisories/28592Vendor Advisory
- http://secunia.com/advisories/28621Vendor Advisory
- http://secunia.com/advisories/28718
- http://secunia.com/advisories/28843
- http://secunia.com/advisories/28885
- http://secunia.com/advisories/28941
- http://secunia.com/advisories/29139
- http://secunia.com/advisories/29420
- http://secunia.com/advisories/29622
- http://secunia.com/advisories/29707
- http://secunia.com/advisories/30161
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.