CVE-2017-13722
Summary
| CVE | CVE-2017-13722 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-11 17:29:00 UTC |
| Updated | 2017-11-13 02:29:00 UTC |
| Description | In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure or a crash of the X server. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 1049692 – VUL-0: CVE-2017-13722: libXfont: Missing boundary check in pcfGetProperties | CONFIRM | bugzilla.suse.com | Issue Tracking |
| LibXfont, LibXfont2: Multiple vulnerabilities (GLSA 201711-08) — Gentoo security | GENTOO | security.gentoo.org | |
| Debian -- Security Information -- DSA-3995-1 libxfont | DEBIAN | www.debian.org | |
| www.x.org/releases/individual/lib/libXfont2-2.0.2.tar.bz2 | CONFIRM | www.x.org | Vendor Advisory |
| Bug 1500693 – CVE-2017-13722 libXfont: Insufficient input validation in pcfread.c | CONFIRM | bugzilla.redhat.com | Issue Tracking |
| xorg/lib/libXfont - X font handling library for server & utilities (mirrored from https://gitlab.freedesktop.org/xorg/lib/libxfont) | CONFIRM | cgit.freedesktop.org | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710462 Gentoo Linux LibXfont, LibXfont2 Multiple Vulnerabilities (GLSA 201711-08)