CVE-2007-1351
Multiple font integer overflows (CVE-2007-1352)
Severity Score
8.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
Desbordamiento de enteros en la función bdfReadCharacters en (1) X.Org libXfont before 20070403 y (2) freetype 2.3.2 y permite a usuarios remotos validados ejecutar código de su elección a través de fuentes manipuladas BDF, las cueles dan como resultado un desbordamiento de pila.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-03-08 CVE Reserved
- 2007-04-05 CVE Published
- 2024-03-17 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (70)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=501 | 2018-10-16 | |
http://www.securityfocus.com/bid/23283 | 2018-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Multi Network Firewall Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" | 2.0 Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0" | - |
Affected
| in | Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Linux Search vendor "Mandrakesoft" for product "Mandrake Linux" | 2007 Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007" | - |
Safe
|
Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Multi Network Firewall Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" | 2.0 Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0" | - |
Affected
| in | Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Linux Search vendor "Mandrakesoft" for product "Mandrake Linux" | 2007 Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007" | x86_64 |
Safe
|
Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Multi Network Firewall Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" | 2.0 Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0" | - |
Affected
| in | Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Linux Corporate Server Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" | 3.0 Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "3.0" | - |
Safe
|
Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Multi Network Firewall Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" | 2.0 Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0" | - |
Affected
| in | Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Linux Corporate Server Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" | 3.0 Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "3.0" | x86_64 |
Safe
|
Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Multi Network Firewall Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" | 2.0 Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0" | - |
Affected
| in | Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Linux Corporate Server Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" | 4.0 Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "4.0" | - |
Safe
|
Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Multi Network Firewall Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" | 2.0 Search vendor "Mandrakesoft" for product "Mandrake Multi Network Firewall" and version "2.0" | - |
Affected
| in | Mandrakesoft Search vendor "Mandrakesoft" | Mandrake Linux Corporate Server Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" | 4.0 Search vendor "Mandrakesoft" for product "Mandrake Linux Corporate Server" and version "4.0" | x86_64 |
Safe
|
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 5.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10" | amd64 |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 5.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10" | i386 |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 5.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10" | powerpc |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 5.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "5.10" | sparc |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.06_lts Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts" | amd64 |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.06_lts Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts" | i386 |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.06_lts Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts" | powerpc |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.06_lts Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06_lts" | sparc |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10" | amd64 |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10" | i386 |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10" | powerpc |
Affected
| ||||||
Ubuntu Search vendor "Ubuntu" | Ubuntu Linux Search vendor "Ubuntu" for product "Ubuntu Linux" | 6.10 Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.10" | sparc |
Affected
| ||||||
X.org Search vendor "X.org" | Libxfont Search vendor "X.org" for product "Libxfont" | 1.2.2 Search vendor "X.org" for product "Libxfont" and version "1.2.2" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.3.0 Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.3.0.1 Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0.1" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.3.0.2 Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0.2" | - |
Affected
| ||||||
Rpath Search vendor "Rpath" | Rpath Linux Search vendor "Rpath" for product "Rpath Linux" | 1 Search vendor "Rpath" for product "Rpath Linux" and version "1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | advanced_server |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | advanced_server_ia64 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | enterprise_server |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | enterprise_server_ia64 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | workstation |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | workstation_ia64 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | advanced_servers |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | enterprise_server |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | workstation |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | advanced_server |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | enterprise_server |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | workstation |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 5.0 Search vendor "Redhat" for product "Enterprise Linux" and version "5.0" | desktop |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 5.0 Search vendor "Redhat" for product "Enterprise Linux" and version "5.0" | desktop_workstation |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 5.0 Search vendor "Redhat" for product "Enterprise Linux" and version "5.0" | server |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 3.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "3.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 4.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "4.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Linux Advanced Workstation Search vendor "Redhat" for product "Linux Advanced Workstation" | 2.1 Search vendor "Redhat" for product "Linux Advanced Workstation" and version "2.1" | ia64 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Linux Advanced Workstation Search vendor "Redhat" for product "Linux Advanced Workstation" | 2.1 Search vendor "Redhat" for product "Linux Advanced Workstation" and version "2.1" | itanium |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 3.9 Search vendor "Openbsd" for product "Openbsd" and version "3.9" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 4.0 Search vendor "Openbsd" for product "Openbsd" and version "4.0" | - |
Affected
|