Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 7: DLA-1126-1 Critical: Libxfont Memory Access Threat

debian lts
Calendar Grey October 7, 2017
Dist Debian Esm H88
Enhance libxfont on Debian 7 to resolve two major vulnerabilities related to font processing and rendering.
It was discovered that there two vulnerabilities the library providing font selection and rasterisation, libxfont: * CVE-2017-13720: If a pattern contained a '?' character any char...

Summary

* CVE-2017-13720: If a pattern contained a '?' character any character
in the string is skipped even if it was a '\0'. The rest of the
matching then read invalid memory.

* CVE-2017-13722: A malformed PCF file could cause the library to make
reads from random heap memory that was behind the `strings` buffer,
leading to an application crash or a information leak.

For Debian 7 "Wheezy", this issue has been fixed in libxfont version
1:1.4.5-5+deb7u1.

We recommend that you upgrade your libxfont packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libxfont
Version: 1:1.4.5-5+deb7u1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here