CVE-2013-6462
libXfont: stack-based buffer overflow flaw when parsing Glyph Bitmap Distribution Format (BDF) fonts
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.
Desbordamiento de pila en la función bdfReadCharacters de bitmap/bdfread.c en X.Org libXfont 1.1 hasta 1.4.6 permite a atacantes remotos causar una denegación de servicio (crash) o probablemente ejecutar código de forma arbitraria a través de una cadena larga en el nombre de un caracter de un archivo de fuentes BDF.
The libXfont packages provide the X.Org libXfont runtime library. X.Org is an open source implementation of the X Window System. A stack-based buffer overflow flaw was found in the way the libXfont library parsed Glyph Bitmap Distribution Format fonts. A malicious, local user could exploit this issue to potentially execute arbitrary code with the privileges of the X.Org server. Users of libXfont should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running X.Org server instances must be restarted for the update to take effect.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-11-04 CVE Reserved
- 2014-01-08 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-121: Stack-based Buffer Overflow
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://osvdb.org/101842 | Vdb Entry | |
http://seclists.org/oss-sec/2014/q1/33 | Mailing List |
|
http://secunia.com/advisories/56336 | Third Party Advisory | |
http://secunia.com/advisories/56357 | Third Party Advisory | |
http://secunia.com/advisories/56371 | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html | X_refsource_confirm |
|
http://www.securityfocus.com/bid/64694 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90123 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=4d024ac10f964f6bd372ae0dd14f02772a6e5f63 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2014-01/msg00050.html | 2017-08-29 | |
http://lists.opensuse.org/opensuse-updates/2014-01/msg00052.html | 2017-08-29 | |
http://lists.x.org/archives/xorg-announce/2014-January/002389.html | 2017-08-29 | |
http://rhn.redhat.com/errata/RHSA-2014-0018.html | 2017-08-29 | |
http://secunia.com/advisories/56240 | 2017-08-29 | |
http://www.debian.org/security/2014/dsa-2838 | 2017-08-29 | |
http://www.ubuntu.com/usn/USN-2078-1 | 2017-08-29 | |
https://access.redhat.com/security/cve/CVE-2013-6462 | 2014-01-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1048044 | 2014-01-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.1.0 Search vendor "X" for product "Libxfont" and version "1.1.0" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.0 Search vendor "X" for product "Libxfont" and version "1.2.0" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.1 Search vendor "X" for product "Libxfont" and version "1.2.1" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.2 Search vendor "X" for product "Libxfont" and version "1.2.2" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.3 Search vendor "X" for product "Libxfont" and version "1.2.3" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.4 Search vendor "X" for product "Libxfont" and version "1.2.4" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.5 Search vendor "X" for product "Libxfont" and version "1.2.5" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.6 Search vendor "X" for product "Libxfont" and version "1.2.6" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.7 Search vendor "X" for product "Libxfont" and version "1.2.7" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.8 Search vendor "X" for product "Libxfont" and version "1.2.8" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.2.9 Search vendor "X" for product "Libxfont" and version "1.2.9" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.3.0 Search vendor "X" for product "Libxfont" and version "1.3.0" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.3.1 Search vendor "X" for product "Libxfont" and version "1.3.1" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.3.2 Search vendor "X" for product "Libxfont" and version "1.3.2" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.3.3 Search vendor "X" for product "Libxfont" and version "1.3.3" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.3.4 Search vendor "X" for product "Libxfont" and version "1.3.4" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.4.0 Search vendor "X" for product "Libxfont" and version "1.4.0" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.4.1 Search vendor "X" for product "Libxfont" and version "1.4.1" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.4.2 Search vendor "X" for product "Libxfont" and version "1.4.2" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.4.3 Search vendor "X" for product "Libxfont" and version "1.4.3" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.4.4 Search vendor "X" for product "Libxfont" and version "1.4.4" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.4.5 Search vendor "X" for product "Libxfont" and version "1.4.5" | - |
Affected
| ||||||
X Search vendor "X" | Libxfont Search vendor "X" for product "Libxfont" | 1.4.6 Search vendor "X" for product "Libxfont" and version "1.4.6" | - |
Affected
|