Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxfont | Aug 30, 2017 | May 15, 2014 |
| Centos_linux | — | Upgrade libXfontUpgrade libXfont-devel | Dec 1, 2016 | May 15, 2014 |
| Debian | — | Upgrade libxfont | Jul 30, 2024 | May 15, 2014 |
| Freebsd | — | Upgrade linux-f10-xorg-libsUpgrade libXfontUpgrade linux-c6-xorg-libs | Dec 10, 2025 | May 13, 2014 |
| Gentoo Linux | — | Upgrade x11-libs/libXfont. | Oct 30, 2017 | May 15, 2014 |
| Oracle Solaris | — | Upgrade x11/library/libxfont to version 1.4.5-0.175.1.21.0.3.1357 on Solaris 11.1 | May 29, 2017 | May 15, 2014 |
| Oracle_linux | — | Upgrade libXfont-develUpgrade libXfont | Oct 16, 2024 | May 15, 2014 |
| Suse | — | Upgrade xorg-x11-libs-x86Upgrade xorg-x11-devel-32bitUpgrade xorg-x11-develUpgrade xorg-x11-libs-32bitUpgrade xorg-x11-libsUpgrade libXfont-develUpgrade libXfont1 | Dec 18, 2015 | May 15, 2014 |
| Ubuntu | — | Upgrade libxfont1 | Nov 8, 2024 | May 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub