SUSE-SU-2018:0334-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0334-1
SUSE-SU-2018:0334-1
Summary: Security update for libXfont
Details: This update for libXfont fixes several issues. These security issues were fixed: - CVE-2017-13720: Improper check for end of string in PatterMatch caused invalid reads (bsc#1054285) - CVE-2017-13722: Malformed PCF file could have caused DoS or leak information (bsc#1049692) - Prevent the X server from accessing arbitrary files as root. It is not possible to leak information, but special files can be touched allowing for causing side effects (bsc#1050459)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180334-1/, https://bugzilla.suse.com/1049692, https://bugzilla.suse.com/1050459, https://bugzilla.suse.com/1054285, https://www.suse.com/security/cve/CVE-2017-13720, https://www.suse.com/security/cve/CVE-2017-13722
Affected packages
Package
Name: libXfont
Purl: pkg:rpm/suse/libXfont&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
