Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-0083Improper Restriction of Operations within the Bounds of a Memory Buffer in Project X11r6

12 documents6 sources
Severity
10.0CRITICALNVD
EPSS
2.4%
top 14.90%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 3
Latest updateApr 29

Description

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDxfree86_project/x11r66 versions+5
NVDopenbsd/openbsd3.3, 3.4+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-275v-77j5-j2rj: Buffer overflow in ReadFontAlias from dirfile2022-04-29
CVEList
CVE-2004-0083: Buffer overflow in ReadFontAlias from dirfile2004-02-14

💥Exploits & PoCs

1
Exploit-DB
XFree86 4.3 - Font Information File Buffer Overflow2004-11-10

📋Vendor Advisories

3
Red Hat
security flaw2004-02-13
Red Hat
security flaw2004-02-12
Red Hat
security flaw2004-02-08

💬Community

5
Bugzilla
CVE-2004-0083 security flaw2018-08-16
Bugzilla
CVE-2004-0106 security flaw2018-08-16
Bugzilla
CVE-2004-0084 security flaw2018-08-16
Bugzilla
CAN-2004-0083 XFree86 font.alias overflow2004-02-04
Bugzilla
CAN-2004-0083, CAN-2004-0084, CAN-2004-0106 - XFree86 font.alias buffer overflow2004-02-04
CVE-2004-0083 — Xfree86 Project X11r6 vulnerability | cvebase