Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
XFree86 CopyISOLatin1Lowered Font_Name本地缓冲区溢出漏洞
Vulnerability Description
XFree86是一款流行的X服务器。 XFree86 X Windows系统当处理'font.alias'文件时缺少正确的边界检查,本地攻击者可以利用这个漏洞进行缓冲区溢出攻击,可提升权限。 问题存在于CopyISOLatin1Lowered()函数处理'font_name'缓冲区时。当解析'font.alias'文件时,ReadFontAlias()函数使用输入字符串长度作为拷贝的限制长度来代替存储缓冲区的大小,恶意用户可以构建畸形'font.alias'文件,诱使用户解析,以root用户权限执行任意指
CVSS Information
N/A
Vulnerability Type
N/A