// For flags

CVE-2007-1351

Multiple font integer overflows (CVE-2007-1352)

Severity Score

8.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.

Desbordamiento de enteros en la función bdfReadCharacters en (1) X.Org libXfont before 20070403 y (2) freetype 2.3.2 y permite a usuarios remotos validados ejecutar código de su elección a través de fuentes manipuladas BDF, las cueles dan como resultado un desbordamiento de pila.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-03-08 CVE Reserved
  • 2007-04-05 CVE Published
  • 2024-03-17 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
CAPEC
References (70)
URL Tag Source
http://issues.foresightlinux.org/browse/FL-223 X_refsource_confirm
http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html Mailing List
http://secunia.com/advisories/24745 Third Party Advisory
http://secunia.com/advisories/24756 Third Party Advisory
http://secunia.com/advisories/24758 Third Party Advisory
http://secunia.com/advisories/24765 Third Party Advisory
http://secunia.com/advisories/24768 Third Party Advisory
http://secunia.com/advisories/24771 Third Party Advisory
http://secunia.com/advisories/24772 Third Party Advisory
http://secunia.com/advisories/24776 Third Party Advisory
http://secunia.com/advisories/24791 Third Party Advisory
http://secunia.com/advisories/24885 Third Party Advisory
http://secunia.com/advisories/24889 Third Party Advisory
http://secunia.com/advisories/24921 Third Party Advisory
http://secunia.com/advisories/24996 Third Party Advisory
http://secunia.com/advisories/25004 Third Party Advisory
http://secunia.com/advisories/25006 Third Party Advisory
http://secunia.com/advisories/25096 Third Party Advisory
http://secunia.com/advisories/25195 Third Party Advisory
http://secunia.com/advisories/25216 Third Party Advisory
http://secunia.com/advisories/25305 Third Party Advisory
http://secunia.com/advisories/25495 Third Party Advisory
http://secunia.com/advisories/28333 Third Party Advisory
http://secunia.com/advisories/30161 Third Party Advisory
http://secunia.com/advisories/33937 Third Party Advisory
http://sourceforge.net/project/shownotes.php?group_id=3157&release_id=498954 X_refsource_confirm
http://sourceforge.net/project/shownotes.php?release_id=498954 X_refsource_confirm
http://support.apple.com/kb/HT3438 X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2007-193.htm X_refsource_confirm
http://www.securityfocus.com/archive/1/464686/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/464816/100/0/threaded Mailing List
http://www.securityfocus.com/bid/23300 Vdb Entry
http://www.securityfocus.com/bid/23402 Vdb Entry
http://www.securitytracker.com/id?1017857 Vdb Entry
http://www.vupen.com/english/advisories/2007/1217 Vdb Entry
http://www.vupen.com/english/advisories/2007/1264 Vdb Entry
http://www.vupen.com/english/advisories/2007/1548 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/33417 Vdb Entry
https://issues.rpath.com/browse/RPL-1213 X_refsource_confirm
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11266 Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1810 Signature
URL Date SRC
URL Date SRC
http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html 2018-10-16
http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html 2018-10-16
http://rhn.redhat.com/errata/RHSA-2007-0125.html 2018-10-16
http://secunia.com/advisories/24741 2018-10-16
http://secunia.com/advisories/24770 2018-10-16
http://security.gentoo.org/glsa/glsa-200705-02.xml 2018-10-16
http://security.gentoo.org/glsa/glsa-200705-10.xml 2018-10-16
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.626733 2018-10-16
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1 2018-10-16
http://www.debian.org/security/2007/dsa-1294 2018-10-16
http://www.debian.org/security/2008/dsa-1454 2018-10-16
http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml 2018-10-16
http://www.mandriva.com/security/advisories?name=MDKSA-2007:079 2018-10-16
http://www.mandriva.com/security/advisories?name=MDKSA-2007:080 2018-10-16
http://www.mandriva.com/security/advisories?name=MDKSA-2007:081 2018-10-16
http://www.novell.com/linux/security/advisories/2007_27_x.html 2018-10-16
http://www.novell.com/linux/security/advisories/2007_6_sr.html 2018-10-16
http://www.openbsd.org/errata39.html#021_xorg 2018-10-16
http://www.openbsd.org/errata40.html#011_xorg 2018-10-16
http://www.redhat.com/support/errata/RHSA-2007-0126.html 2018-10-16
http://www.redhat.com/support/errata/RHSA-2007-0132.html 2018-10-16
http://www.redhat.com/support/errata/RHSA-2007-0150.html 2018-10-16
http://www.trustix.org/errata/2007/0013 2018-10-16
http://www.ubuntu.com/usn/usn-448-1 2018-10-16
https://access.redhat.com/security/cve/CVE-2007-1351 2007-04-16
https://bugzilla.redhat.com/show_bug.cgi?id=235265 2007-04-16
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Multi Network Firewall
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall"
2.0
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0"
-
Affected
in Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2007
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007"
-
Safe
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Multi Network Firewall
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall"
2.0
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0"
-
Affected
in Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2007
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007"
x86_64
Safe
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Multi Network Firewall
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall"
2.0
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0"
-
Affected
in Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux Corporate Server
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server"
3.0
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "3.0"
-
Safe
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Multi Network Firewall
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall"
2.0
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0"
-
Affected
in Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux Corporate Server
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server"
3.0
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "3.0"
x86_64
Safe
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Multi Network Firewall
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall"
2.0
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0"
-
Affected
in Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux Corporate Server
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server"
4.0
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "4.0"
-
Safe
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Multi Network Firewall
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall"
2.0
Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0"
-
Affected
in Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux Corporate Server
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server"
4.0
Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "4.0"
x86_64
Safe
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
5.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10"
amd64
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
5.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10"
i386
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
5.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10"
powerpc
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
5.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10"
sparc
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.06_lts
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts"
amd64
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.06_lts
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts"
i386
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.06_lts
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts"
powerpc
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.06_lts
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts"
sparc
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10"
amd64
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10"
i386
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10"
powerpc
Affected
Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10"
sparc
Affected
X.org
Search vendor "X.org"
Libxfont
Search vendor "X.org" for product "Libxfont"
1.2.2
Search vendor "X.org" for product "Libxfont" and version "1.2.2"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.3.0
Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.3.0.1
Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0.1"
-
Affected
Xfree86 Project
Search vendor "Xfree86 Project"
X11r6
Search vendor "Xfree86 Project" for product "X11r6"
4.3.0.2
Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0.2"
-
Affected
Rpath
Search vendor "Rpath"
Rpath Linux
Search vendor "Rpath" for product "Rpath Linux"
1
Search vendor "Rpath" for product "Rpath Linux" and version "1"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
2.1
Search vendor "Redhat" for product "Enterprise Linux" and version "2.1"
advanced_server
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
2.1
Search vendor "Redhat" for product "Enterprise Linux" and version "2.1"
advanced_server_ia64
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
2.1
Search vendor "Redhat" for product "Enterprise Linux" and version "2.1"
enterprise_server
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
2.1
Search vendor "Redhat" for product "Enterprise Linux" and version "2.1"
enterprise_server_ia64
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
2.1
Search vendor "Redhat" for product "Enterprise Linux" and version "2.1"
workstation
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
2.1
Search vendor "Redhat" for product "Enterprise Linux" and version "2.1"
workstation_ia64
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
3.0
Search vendor "Redhat" for product "Enterprise Linux" and version "3.0"
advanced_servers
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
3.0
Search vendor "Redhat" for product "Enterprise Linux" and version "3.0"
enterprise_server
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
3.0
Search vendor "Redhat" for product "Enterprise Linux" and version "3.0"
workstation
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
4.0
Search vendor "Redhat" for product "Enterprise Linux" and version "4.0"
advanced_server
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
4.0
Search vendor "Redhat" for product "Enterprise Linux" and version "4.0"
enterprise_server
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
4.0
Search vendor "Redhat" for product "Enterprise Linux" and version "4.0"
workstation
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
5.0
Search vendor "Redhat" for product "Enterprise Linux" and version "5.0"
desktop
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
5.0
Search vendor "Redhat" for product "Enterprise Linux" and version "5.0"
desktop_workstation
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
5.0
Search vendor "Redhat" for product "Enterprise Linux" and version "5.0"
server
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Desktop
Search vendor "Redhat" for product "Enterprise Linux Desktop"
3.0
Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "3.0"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Desktop
Search vendor "Redhat" for product "Enterprise Linux Desktop"
4.0
Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "4.0"
-
Affected
Redhat
Search vendor "Redhat"
Linux Advanced Workstation
Search vendor "Redhat" for product "Linux Advanced Workstation"
2.1
Search vendor "Redhat" for product "Linux Advanced Workstation" and version "2.1"
ia64
Affected
Redhat
Search vendor "Redhat"
Linux Advanced Workstation
Search vendor "Redhat" for product "Linux Advanced Workstation"
2.1
Search vendor "Redhat" for product "Linux Advanced Workstation" and version "2.1"
itanium
Affected
Openbsd
Search vendor "Openbsd"
Openbsd
Search vendor "Openbsd" for product "Openbsd"
3.9
Search vendor "Openbsd" for product "Openbsd" and version "3.9"
-
Affected
Openbsd
Search vendor "Openbsd"
Openbsd
Search vendor "Openbsd" for product "Openbsd"
4.0
Search vendor "Openbsd" for product "Openbsd" and version "4.0"
-
Affected