FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  514534
Date:      2019-10-15
Time:      14:43:01Z
Committer: kai

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
f7d79fac-cd49-11e4-898f-bcaec565249clibXfont -- BDF parsing issues

Alan Coopersmith reports:

Ilja van Sprundel, a security researcher with IOActive, has discovered an issue in the parsing of BDF font files by libXfont. Additional testing by Alan Coopersmith and William Robinet with the American Fuzzy Lop (afl) tool uncovered two more issues in the parsing of BDF font files.

As libXfont is used by the X server to read font files, and an unprivileged user with access to the X server can tell the X server to read a given font file from a path of their choosing, these vulnerabilities have the potential to allow unprivileged users to run code with the privileges of the X server (often root access).


Discovery 2015-03-17
Entry 2015-03-18
Modified 2016-01-31
libXfont
lt 1.5.1

linux-c6-xorg-libs
lt 7.4_4

linux-f10-xorg-libs
lt 7.4_4

http://lists.x.org/archives/xorg-announce/2015-March/002550.html
CVE-2015-1802
CVE-2015-1803
CVE-2015-1804