← Back to CVE List
Vulnerability Intelligence Report

CVE-2007-1351

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.

No Active Exploit Signals
CVSS Base Score
8.5
HIGH
EPSS Probability:5.59%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
ubuntu ubuntu_linux 5.10, 6.06_lts, 6.10
x.org libxfont 1.2.2
xfree86_project x11r6 4.3.0, 4.3.0.1, 4.3.0.2
rpath rpath_linux 1
redhat enterprise_linux 2.1, 3.0, 4.0, 5.0
redhat enterprise_linux_desktop 3.0, 4.0
redhat linux_advanced_workstation 2.1
openbsd openbsd 3.9, 4.0
mandrakesoft mandrake_linux 2007
mandrakesoft mandrake_linux_corporate_server 3.0, 4.0
mandrakesoft mandrake_multi_network_firewall 2.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
5.586%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2007-03-08T00:00:00
Published2007-04-06T01:00:00
Patch Date2007-04-03
Last Updated2024-08-07T12:50:35

LINK COPIED TO CLIPBOARD