CVE-2008-0006
published 2008-01-18CVE-2008-0006: Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.11%
91.4th percentile
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxfont | < libxfont 1:1.3.1-2 (bookworm) | libxfont 1:1.3.1-2 (bookworm) |
| debian | xorg-server | < libxfont 1:1.3.1-2 (bookworm) | libxfont 1:1.3.1-2 (bookworm) |
| x.org | libxfont | >= 0 < 1:1.3.1-2 | 1:1.3.1-2 |
| x.org | libxfont | >= 0 < 1:1.3.1-2 | 1:1.3.1-2 |
| x.org | libxfont | >= 0 < 1:1.3.1-2 | 1:1.3.1-2 |
| x.org | libxfont | >= 0 < 1:1.3.1-2 | 1:1.3.1-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xorg-server | >= 0 < 2:1.4.1~git20080105-2 | 2:1.4.1~git20080105-2 |
| x.org | xserver | <= 1.4 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu9.3CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
vendor_vmware·2009-04-10·CVSS 4.6
CVE-2008-4916 [MEDIUM] VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
VMSA-2009-0006: VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability
a. Host code execution vulnerability from a guest operating system A critical vulnerability in the virtual machine display function might allow a guest operating system to run code on the host. This issue is different from the vulnerability in a guest virtual device driver reported in VMware security advisory VMSA-2009-0005 on 2009-04-03. That vulnerability can cause a potential denial of service and is identified by CVE-2008-4916. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-1244 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product ============= Pr
Ubuntu
X.org regression
vendor_ubuntu·2008-01-19·CVSS 9.3
[CRITICAL] X.org regression
Title: X.org regression
Summary: X.org regression
USN-571-1 fixed vulnerabilities in X.org. The upstream fixes were
incomplete, and under certain situations, applications using the MIT-SHM
extension (e.g. Java, wxWidgets) would crash with BadAlloc X errors.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
function arguments. An authenticated attacker could send specially
crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
CVE-2007-6428, CVE-2007-6429)
It was discovered that the X.org server did not use user privileges when
attempting to open security policy files. Local attackers c
Ubuntu
X.org vulnerabilities
vendor_ubuntu·2008-01-18·CVSS 9.3
CVE-2008-0006 [CRITICAL] X.org vulnerabilities
Title: X.org vulnerabilities
Summary: X.org vulnerabilities
Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
function arguments. An authenticated attacker could send specially
crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
CVE-2007-6428, CVE-2007-6429)
It was discovered that the X.org server did not use user privileges when
attempting to open security policy files. Local attackers could exploit
this to probe for files in directories they would not normally be able
to access. (CVE-2007-5958)
It was discovered that the PCF font handling code did not correctly
validate the size of fonts. An authenticated attacker could load a
specially crafted font and gain additional privi
Red Hat
Xorg / XFree86 PCF font parser buffer overflow
vendor_redhat·2008-01-17·CVSS 7.5
CVE-2008-0006 [HIGH] Xorg / XFree86 PCF font parser buffer overflow
Xorg / XFree86 PCF font parser buffer overflow
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.
Debian
CVE-2008-0006: libxfont - Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXf...
vendor_debian·2008·CVSS 7.5
CVE-2008-0006 [HIGH] CVE-2008-0006: libxfont - Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXf...
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.
Scope: local
bookworm: resolved (fixed in 1:1.3.1-2)
bullseye: resolved (fixed in 1:1.3.1-2)
forky: resolved (fixed in 1:1.3.1-2)
sid: resolved (fixed in 1:1.3.1-2)
trixie: resolved (fixed in 1:1.3.1-2)
GHSA
GHSA-8jcc-7w3m-qv8c: Buffer overflow in (1) X
ghsa_unreviewed·2022-05-01
CVE-2008-0006 [HIGH] CWE-119 GHSA-8jcc-7w3m-qv8c: Buffer overflow in (1) X
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.
OSV
CVE-2008-0006: Buffer overflow in (1) X
osv·2008-01-18·CVSS 7.5
CVE-2008-0006 [HIGH] CVE-2008-0006: Buffer overflow in (1) X
Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.
No detection rules found.
Bugzilla
nx: Appears to embed a vulnerable version of libXfont prone to CVE-2008-0006
bugzilla·2010-12-03·CVSS 7.5
CVE-2008-0006 [HIGH] nx: Appears to embed a vulnerable version of libXfont prone to CVE-2008-0006
nx: Appears to embed a vulnerable version of libXfont prone to CVE-2008-0006
This package appears to embed an old and vulnerable version of libXfont which
is prone to CVE-2008-0006
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0006
There is also an older vulnerability in libXfont CVE-2006-3467 which I have not
verified is or isn't present in nx.
Version-Release number of selected component (if applicable):
Name: nx
Arch: i686
Version: 3.3.0
Release 38.fc12
Additional info:
It has been hard to figure out exactly which version of libXfont is in nx.
Instead I have done a diff between the current Fedora release of libXfont
(1.4.1) and the nx version. Note that the CVE alert says that the version of
libXfont that is first fixed is in 1.4.1.
The diff shows a number of changes, b
Bugzilla
CVE-2008-2368 Certificate System: plain text passwords stored in debug log
bugzilla·2008-06-18·CVSS 2.1
CVE-2008-2368 [LOW] CVE-2008-2368 Certificate System: plain text passwords stored in debug log
CVE-2008-2368 Certificate System: plain text passwords stored in debug log
It was discovered that Red Hat Certificate System may store plain text passwords
in multiple debug log files (such as UserDirEnrollment password or RA wizard
installer log).
This problem allows any local user to extract plain text passwords from the Red
Hat Certificate System debug log files.
Discussion:
Lifting embargo.
---
This issue was addressed in:
Red Hat Certificate System:
http://rhn.redhat.com/errata/RHSA-2009-0006.html
http://rhn.redhat.com/errata/RHSA-2009-0007.html
Bugzilla
CVE-2008-2367 Certificate System: insecure config file permissions
bugzilla·2008-06-18·CVSS 2.1
CVE-2008-2367 [LOW] CVE-2008-2367 Certificate System: insecure config file permissions
CVE-2008-2367 Certificate System: insecure config file permissions
It was discovered that Red Hat Certificate System use insecure default file
permissions on configuration files (such as password.conf) that may contain
authentication credentials or other sensitive information that should only be
accessible to administrative and service users.
This problem allows any local user to read Red Hat Certificate System
configuration files.
Discussion:
Lifting embargo.
---
This issue was addressed in:
Red Hat Certificate System:
http://rhn.redhat.com/errata/RHSA-2009-0006.html
http://rhn.redhat.com/errata/RHSA-2009-0007.html
Bugzilla
CVE-2008-0006 Xorg / XFree86 PCF font parser buffer overflow
bugzilla·2008-01-08·CVSS 7.5
CVE-2008-0006 [HIGH] CVE-2008-0006 Xorg / XFree86 PCF font parser buffer overflow
CVE-2008-0006 Xorg / XFree86 PCF font parser buffer overflow
Takuya Shiozaki of CodeBlog discovered a heap based buffer overflow flaw in
X.org's PCF font handler.
This flaw is being tracked as VU#203220 by CERT.
Discussion:
Lifting embargo:
http://lists.freedesktop.org/archives/xorg/2008-January/031918.html
---
libXfont-1.3.1-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
libXfont-1.2.9-3.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0064.html
http://rhn.redhat.com/errata/RHSA-2008-0030.html
http://rhn.redhat.com/errata/RH
http://bugs.gentoo.org/show_bug.cgi?id=204362http://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321http://jvn.jp/en/jp/JVN88935101/index.htmlhttp://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001043.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/28273http://secunia.com/advisories/28500http://secunia.com/advisories/28532http://secunia.com/advisories/28535http://secunia.com/advisories/28536http://secunia.com/advisories/28540http://secunia.com/advisories/28542http://secunia.com/advisories/28544http://secunia.com/advisories/28550http://secunia.com/advisories/28571http://secunia.com/advisories/28592http://secunia.com/advisories/28621http://secunia.com/advisories/28718http://secunia.com/advisories/28843http://secunia.com/advisories/28885http://secunia.com/advisories/28941http://secunia.com/advisories/29139http://secunia.com/advisories/29420http://secunia.com/advisories/29622http://secunia.com/advisories/29707http://secunia.com/advisories/30161http://secunia.com/advisories/32545http://security.gentoo.org/glsa/glsa-200801-09.xmlhttp://security.gentoo.org/glsa/glsa-200804-05.xmlhttp://securitytracker.com/id?1019232http://sunsolve.sun.com/search/document.do?assetkey=1-26-103192-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-201230-1http://support.avaya.com/elmodocs2/security/ASA-2008-038.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-077.htmhttp://www.gentoo.org/security/en/glsa/glsa-200805-07.xmlhttp://www.kb.cert.org/vuls/id/203220http://www.mandriva.com/security/advisories?name=MDVSA-2008:021http://www.mandriva.com/security/advisories?name=MDVSA-2008:022http://www.mandriva.com/security/advisories?name=MDVSA-2008:024http://www.openbsd.org/errata41.html#012_xorghttp://www.openbsd.org/errata42.html#006_xorghttp://www.redhat.com/support/errata/RHSA-2008-0029.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0030.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0064.htmlhttp://www.securityfocus.com/archive/1/487335/100/0/threadedhttp://www.securityfocus.com/bid/27336http://www.securityfocus.com/bid/27352http://www.vupen.com/english/advisories/2008/0179http://www.vupen.com/english/advisories/2008/0184http://www.vupen.com/english/advisories/2008/0497/referenceshttp://www.vupen.com/english/advisories/2008/0703http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/3000http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile112539&label=AIX%20X%20server%20multiple%20vulnerabilitieshttps://bugzilla.redhat.com/show_bug.cgi?id=428044https://exchange.xforce.ibmcloud.com/vulnerabilities/39767https://issues.rpath.com/browse/RPL-2010https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10021https://usn.ubuntu.com/571-1/https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00674.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00771.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=204362http://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321http://jvn.jp/en/jp/JVN88935101/index.htmlhttp://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001043.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.freedesktop.org/archives/xorg/2008-January/031918.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/28273http://secunia.com/advisories/28500http://secunia.com/advisories/28532http://secunia.com/advisories/28535http://secunia.com/advisories/28536http://secunia.com/advisories/28540http://secunia.com/advisories/28542http://secunia.com/advisories/28544http://secunia.com/advisories/28550http://secunia.com/advisories/28571http://secunia.com/advisories/28592http://secunia.com/advisories/28621http://secunia.com/advisories/28718http://secunia.com/advisories/28843http://secunia.com/advisories/28885http://secunia.com/advisories/28941http://secunia.com/advisories/29139http://secunia.com/advisories/29420http://secunia.com/advisories/29622http://secunia.com/advisories/29707http://secunia.com/advisories/30161http://secunia.com/advisories/32545http://security.gentoo.org/glsa/glsa-200801-09.xmlhttp://security.gentoo.org/glsa/glsa-200804-05.xml
+ 34 more references
2008-01-18
Published