A local overflow exists in XFree86. The CopyISOLatin1Lowered() function fails to validate the length of the font_name buffer when reading the 'font.alias' file. With a specially crafted malformed file, an attacker can execute arbitrary code resulting in a loss of integrity
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, XFree86 Project has released a patch to address this vulnerability.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.