In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxfontUpgrade libxfont2 | Jan 15, 2018 | Dec 1, 2017 |
| Debian | — | Upgrade libxfont | Jan 27, 2022 | Dec 1, 2017 |
| Freebsd | — | Upgrade libXfont2Upgrade libXfont | Dec 20, 2017 | Dec 17, 2017 |
| Gentoo Linux | — | Upgrade x11-libs/libXfont.Upgrade x11-libs/libXfont2. | Jan 9, 2018 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp2 | — | — | Dec 4, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp3 | — | — | Dec 18, 2019 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp5 | — | — | Nov 19, 2019 | Dec 1, 2017 |
| Oracle Solaris | — | Upgrade x11/library/libxcursor to version 1.1.15-0.175.3.31.0.2.1545 on Solaris 11.3Upgrade x11/library/libxfont to version 1.5.4-0.175.3.31.0.2.1545 on Solaris 11.3 | Apr 18, 2018 | Dec 1, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 25, 2017 |
| Suse | — | Upgrade libXfont2-2Upgrade libXfont-develUpgrade libXfont2-develUpgrade libXfont1 | May 20, 2018 | Nov 29, 2017 |
| Ubuntu | — | Upgrade libxfont1Upgrade libxfont2Upgrade libxfont2 (Ubuntu Pro)Upgrade libxfont1 (Ubuntu Pro) | Nov 29, 2017 | Nov 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub