CVE-2007-1352: Integer Overflow
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1352?
CVE-2007-1352 has been assigned a moderate severity rating due to the potential for remote authenticated users to execute arbitrary code.
How do I fix CVE-2007-1352?
To mitigate CVE-2007-1352, users should update to the latest version of X.Org libXfont or apply patches provided by their Linux distribution.
Who is affected by CVE-2007-1352?
CVE-2007-1352 affects users of X.Org libXfont versions prior to 20070403 and various Red Hat Enterprise Linux and Ubuntu versions.
What types of attacks are possible due to CVE-2007-1352?
An attacker can exploit CVE-2007-1352 by creating a malicious fonts.dir file, leading to a heap overflow and potential arbitrary code execution.
What versions of software are vulnerable to CVE-2007-1352?
Vulnerable versions include X.Org libXfont versions below 1.2.2 and specific versions of Red Hat Enterprise Linux and Ubuntu.