In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-libxfontalpine-linux-upgrade-libxfont2 | Jan 15, 2018 | Dec 1, 2017 | |
| Debian | debian-upgrade-libxfont | Jan 27, 2022 | Dec 1, 2017 | |
| Freebsd | freebsd-upgrade-package-libxfontfreebsd-upgrade-package-libxfont2 | Dec 20, 2017 | Dec 17, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-x11-libs-libxfontgentoo-linux-upgrade-x11-libs-libxfont2 | Jan 9, 2018 | Dec 1, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libxfont | Dec 4, 2019 | Dec 1, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-libxfont | Dec 18, 2019 | Dec 1, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-libxfont | Nov 19, 2019 | Dec 1, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-x11-library-libxcursor-1-1-15-0-175-3-31-0-2-1545oracle-solaris-11-3-upgrade-x11-library-libxfont-1-5-4-0-175-3-31-0-2-1545 | Apr 18, 2018 | Dec 1, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Nov 25, 2017 | |
| Suse | — | suse-upgrade-libxfont-develsuse-upgrade-libxfont1suse-upgrade-libxfont2-2suse-upgrade-libxfont2-devel | May 20, 2018 | Nov 29, 2017 |
| Ubuntu | ubuntu-pro-upgrade-libxfont1ubuntu-pro-upgrade-libxfont2ubuntu-upgrade-libxfont1ubuntu-upgrade-libxfont2 | Nov 29, 2017 | Nov 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub