CVE-2007-1351
NONE EPSS 91.9%
Published Apr 6, 200719y ago · Modified Jun 16, 20262w ago
Published Apr 6, 2007 19y ago
Last Modified Jun 16, 2026 2w ago
Description
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
Threat Intelligence
EPSS Exploit Probability
91.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-189
Affected Products 45
| Vendor | Product | Version | Range |
|---|---|---|---|
| ubuntu | ubuntu_linux | 5.10 | any |
| ubuntu | ubuntu_linux | 5.10 | any |
| ubuntu | ubuntu_linux | 5.10 | any |
| ubuntu | ubuntu_linux | 5.10 | any |
| ubuntu | ubuntu_linux | 6.06_lts | any |
| ubuntu | ubuntu_linux | 6.06_lts | any |
| ubuntu | ubuntu_linux | 6.06_lts | any |
| ubuntu | ubuntu_linux | 6.06_lts | any |
| ubuntu | ubuntu_linux | 6.10 | any |
| ubuntu | ubuntu_linux | 6.10 | any |
| ubuntu | ubuntu_linux | 6.10 | any |
| ubuntu | ubuntu_linux | 6.10 | any |
| x.org | libxfont | 1.2.2 | any |
| xfree86_project | x11r6 | 4.3.0 | any |
| xfree86_project | x11r6 | 4.3.0.1 | any |
| xfree86_project | x11r6 | 4.3.0.2 | any |
| rpath | rpath_linux | 1 | any |
| redhat | enterprise_linux | 2.1 | any |
| redhat | enterprise_linux | 2.1 | any |
| redhat | enterprise_linux | 2.1 | any |
| redhat | enterprise_linux | 2.1 | any |
| redhat | enterprise_linux | 2.1 | any |
| redhat | enterprise_linux | 2.1 | any |
| redhat | enterprise_linux | 3.0 | any |
| redhat | enterprise_linux | 3.0 | any |
| redhat | enterprise_linux | 3.0 | any |
| redhat | enterprise_linux | 4.0 | any |
| redhat | enterprise_linux | 4.0 | any |
| redhat | enterprise_linux | 4.0 | any |
| redhat | enterprise_linux | 5.0 | any |
| redhat | enterprise_linux | 5.0 | any |
| redhat | enterprise_linux | 5.0 | any |
| redhat | enterprise_linux_desktop | 3.0 | any |
| redhat | enterprise_linux_desktop | 4.0 | any |
| redhat | linux_advanced_workstation | 2.1 | any |
| redhat | linux_advanced_workstation | 2.1 | any |
| openbsd | openbsd | 3.9 | any |
| openbsd | openbsd | 4.0 | any |
| mandrakesoft | mandrake_linux | 2007 | any |
| mandrakesoft | mandrake_linux | 2007 | any |
| mandrakesoft | mandrake_linux_corporate_server | 3.0 | any |
| mandrakesoft | mandrake_linux_corporate_server | 3.0 | any |
| mandrakesoft | mandrake_linux_corporate_server | 4.0 | any |
| mandrakesoft | mandrake_linux_corporate_server | 4.0 | any |
| mandrakesoft | mandrake_multi_network_firewall | 2.0 | any |
References 68
- issues.foresightlinux.org http://issues.foresightlinux.org/browse/FL-223
- labs.idefense.com http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=501
- lists.apple.com http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html
- lists.apple.com http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html
- lists.freedesktop.org http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html
- rhn.redhat.com http://rhn.redhat.com/errata/RHSA-2007-0125.html
- secunia.com http://secunia.com/advisories/24741
- secunia.com http://secunia.com/advisories/24745
- secunia.com http://secunia.com/advisories/24756
- secunia.com http://secunia.com/advisories/24758
- secunia.com http://secunia.com/advisories/24765
- secunia.com http://secunia.com/advisories/24768
- secunia.com http://secunia.com/advisories/24770
- secunia.com http://secunia.com/advisories/24771
- secunia.com http://secunia.com/advisories/24772
- secunia.com http://secunia.com/advisories/24776
- secunia.com http://secunia.com/advisories/24791
- secunia.com http://secunia.com/advisories/24885
- secunia.com http://secunia.com/advisories/24889
- secunia.com http://secunia.com/advisories/24921
- secunia.com http://secunia.com/advisories/24996
- secunia.com http://secunia.com/advisories/25004
- secunia.com http://secunia.com/advisories/25006
- secunia.com http://secunia.com/advisories/25096
- secunia.com http://secunia.com/advisories/25195
- secunia.com http://secunia.com/advisories/25216
- secunia.com http://secunia.com/advisories/25305
- secunia.com http://secunia.com/advisories/25495
- secunia.com http://secunia.com/advisories/28333
- secunia.com http://secunia.com/advisories/30161
- secunia.com http://secunia.com/advisories/33937
- security.gentoo.org http://security.gentoo.org/glsa/glsa-200705-02.xml
- security.gentoo.org http://security.gentoo.org/glsa/glsa-200705-10.xml
- slackware.com http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.626733
- sourceforge.net http://sourceforge.net/project/shownotes.php?group_id=3157&release_id=498954
- sourceforge.net http://sourceforge.net/project/shownotes.php?release_id=498954
- sunsolve.sun.com http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1
- support.apple.com http://support.apple.com/kb/HT3438
- support.avaya.com http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm
- support.avaya.com http://support.avaya.com/elmodocs2/security/ASA-2007-193.htm
- debian.org http://www.debian.org/security/2007/dsa-1294
- debian.org http://www.debian.org/security/2008/dsa-1454
- gentoo.org http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml
- mandriva.com http://www.mandriva.com/security/advisories?name=MDKSA-2007:079
- mandriva.com http://www.mandriva.com/security/advisories?name=MDKSA-2007:080
- mandriva.com http://www.mandriva.com/security/advisories?name=MDKSA-2007:081
- novell.com http://www.novell.com/linux/security/advisories/2007_27_x.html
- novell.com http://www.novell.com/linux/security/advisories/2007_6_sr.html
- openbsd.org http://www.openbsd.org/errata39.html#021_xorg
- openbsd.org http://www.openbsd.org/errata40.html#011_xorg
- redhat.com http://www.redhat.com/support/errata/RHSA-2007-0126.html
- redhat.com http://www.redhat.com/support/errata/RHSA-2007-0132.html
- redhat.com http://www.redhat.com/support/errata/RHSA-2007-0150.html
- securityfocus.com http://www.securityfocus.com/archive/1/464686/100/0/threaded
- securityfocus.com http://www.securityfocus.com/archive/1/464816/100/0/threaded
- securityfocus.com http://www.securityfocus.com/bid/23283
- securityfocus.com http://www.securityfocus.com/bid/23300
- securityfocus.com http://www.securityfocus.com/bid/23402
- securitytracker.com http://www.securitytracker.com/id?1017857
- trustix.org http://www.trustix.org/errata/2007/0013/
- ubuntu.com http://www.ubuntu.com/usn/usn-448-1
- vupen.com http://www.vupen.com/english/advisories/2007/1217
- vupen.com http://www.vupen.com/english/advisories/2007/1264
- vupen.com http://www.vupen.com/english/advisories/2007/1548
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/33417
- issues.rpath.com https://issues.rpath.com/browse/RPL-1213
- oval.cisecurity.org https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11266
- oval.cisecurity.org https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1810
Remediation
- labs.idefense.com http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=501
- securityfocus.com http://www.securityfocus.com/bid/23283