LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

xfstt: remote exploits

Package(s):xfstt CVE #(s):CAN-2003-0581 CAN-2003-0625
Created:August 1, 2003 Updated:August 5, 2003
Description: xfstt, a TrueType font server for the X window system was found to contain two classes of vulnerabilities:
  • CAN-2003-0581: a remote attacker could send requests crafted to trigger any of several buffer overruns, causing a denial of service or possibly executing arbitrary code on the server with the privileges of the "nobody" user.

  • CAN-2003-0625: certain invalid data sent during the connection handshake could allow a remote attacker to read certain regions of memory belonging to the xfstt process. This information could be used for fingerprinting, or to aid in exploitation of a different vulnerability.
Alerts:
Debian DSA-360-1 2003-08-01

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds