MGASA-2017-0373
Dashboard / Vulnerabilities / MGASA-2017-0373
MGASA-2017-0373
Summary: Updated libxfont packages fix security vulnerabilities
Details: In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters. (CVE-2017-13720) In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server. (CVE-2017-13722)
References: https://advisories.mageia.org/MGASA-2017-0373.html, https://bugs.mageia.org/show_bug.cgi?id=21834, https://www.debian.org/security/2017/dsa-3995, https://usn.ubuntu.com/usn/usn-3442-1/
Affected packages
Package
Name: libxfont
Purl: pkg:rpm/mageia/libxfont?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
