CVE-2003-0581
EPSS 1.8%xfstt - several vulnerabilities
發布日:2003/8/18修改日:2026/4/28
也稱為:DEBIAN-CVE-2003-0581
描述
X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access.
受影響套件(2)
- Debian/xfsttfrom 0, < 1.5-1
- Debian/xfsttfrom 0, < 1.2.1-3