Overview
A vulnerability in the X.Org server could allow a remote attacker to execute arbitrary code on an affected system.
Description
The X.Org project provides an open source implementation of the X Window System. The server supports bitmapped fonts in various formats, including Portable Compiled Font (PCF) format. A flaw exists in the handling of PCF fonts where the difference between lastCol and firstCol in the PCF_BDF_ENCODINGS table is greater than 255. An attacker with the ability to cause the X server to open a specially crafted PCF font file could cause a buffer overflow in the X server. |
Impact
A remote attacker with an established, authenticated connection to the X server could execute arbitrary code with the privileges of the X server or cause the server to crash. |
Solution
Upgrade or apply a patch from the vendor Patches and updated versions of the software have been released to address this issue. Please see the Systems Affected section of this document for more information. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Takuya Shiozaki working through JPCERT/CC for reporting this vulnerability.
This document was written by Chad R Dougherty.
Other Information
CVE IDs: | CVE-2008-0006 |
Severity Metric: | 11.54 |
Date Public: | 2008-01-17 |
Date First Published: | 2008-03-19 |
Date Last Updated: | 2008-03-19 14:54 UTC |
Document Revision: | 9 |