Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, (4) fs_read_extent_info, (5) fs_read_glyphs, (6) fs_read_list, or (7) fs_read_list_info function.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxfont | Aug 30, 2017 | May 15, 2014 |
| Centos_linux | — | Upgrade libXfontUpgrade libXfont-devel | Dec 1, 2016 | May 15, 2014 |
| Debian | — | Upgrade libxfont | Jul 30, 2024 | May 15, 2014 |
| Freebsd | — | Upgrade linux-f10-xorg-libsUpgrade linux-c6-xorg-libsUpgrade libXfont | Dec 10, 2025 | May 13, 2014 |
| Gentoo Linux | — | Upgrade x11-libs/libXfont. | Oct 30, 2017 | May 15, 2014 |
| Oracle Solaris | — | Upgrade x11/library/libxfont to version 1.4.5-0.175.1.21.0.3.1357 on Solaris 11.1 | May 29, 2017 | May 15, 2014 |
| Oracle_linux | — | Upgrade libXfont-develUpgrade libXfont | Oct 16, 2024 | May 15, 2014 |
| Suse | — | Upgrade xorg-x11-develUpgrade xorg-x11-libsUpgrade xorg-x11-libs-32bitUpgrade xorg-x11-libs-x86Upgrade libXfont1Upgrade libXfont-develUpgrade xorg-x11-devel-32bit | Dec 18, 2015 | May 15, 2014 |
| Ubuntu | — | Upgrade libxfont1 | Nov 8, 2024 | May 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub