Vulnerability Report

CVE-2007-1352

RCE

Title: X.Org Libxfont RCE

RCE

Proof Of Concept

No public PoC currently indexed for CVE-2007-1352.

CWE Category NVD-CWE-noinfo
Published Date Apr 06, 2007
Modified Date Apr 09, 2025
Exploit Status Not Found
Score 3.8 CVSS v2.0
Exploit Probability (EPSS)
1.70%

Vulnerability Summary

CVE-2007-1352: Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.

Impacted Vendors

Reference Links

http://issues.foresightlinux.org/browse/FL-223 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=502 http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html http://rhn.redhat.com/errata/RHSA-2007-0125.html http://secunia.com/advisories/24741 http://secunia.com/advisories/24745 http://secunia.com/advisories/24756 http://secunia.com/advisories/24758 http://secunia.com/advisories/24765 http://secunia.com/advisories/24770 http://secunia.com/advisories/24771 http://secunia.com/advisories/24772 http://secunia.com/advisories/24791 http://secunia.com/advisories/25004 http://secunia.com/advisories/25006 http://secunia.com/advisories/25195 http://secunia.com/advisories/25216 http://secunia.com/advisories/25305 http://secunia.com/advisories/33937 http://security.gentoo.org/glsa/glsa-200705-10.xml http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1 http://support.apple.com/kb/HT3438 http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm http://www.debian.org/security/2007/dsa-1294 http://www.mandriva.com/security/advisories?name=MDKSA-2007:079 http://www.mandriva.com/security/advisories?name=MDKSA-2007:080 http://www.novell.com/linux/security/advisories/2007_27_x.html http://www.openbsd.org/errata39.html#021_xorg http://www.openbsd.org/errata40.html#011_xorg http://www.redhat.com/support/errata/RHSA-2007-0126.html http://www.redhat.com/support/errata/RHSA-2007-0132.html http://www.securityfocus.com/archive/1/464686/100/0/threaded http://www.securityfocus.com/archive/1/464816/100/0/threaded http://www.securityfocus.com/bid/23283 http://www.securityfocus.com/bid/23300 http://www.securitytracker.com/id?1017857 http://www.ubuntu.com/usn/usn-448-1 http://www.vupen.com/english/advisories/2007/1217 http://www.vupen.com/english/advisories/2007/1548 https://exchange.xforce.ibmcloud.com/vulnerabilities/33419 https://issues.rpath.com/browse/RPL-1213 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10523 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13243 http://issues.foresightlinux.org/browse/FL-223 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=502 http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html http://rhn.redhat.com/errata/RHSA-2007-0125.html http://secunia.com/advisories/24741 http://secunia.com/advisories/24745 http://secunia.com/advisories/24756 http://secunia.com/advisories/24758 http://secunia.com/advisories/24765 http://secunia.com/advisories/24770 http://secunia.com/advisories/24771 http://secunia.com/advisories/24772 http://secunia.com/advisories/24791 http://secunia.com/advisories/25004 http://secunia.com/advisories/25006 http://secunia.com/advisories/25195 http://secunia.com/advisories/25216 http://secunia.com/advisories/25305 http://secunia.com/advisories/33937 http://security.gentoo.org/glsa/glsa-200705-10.xml http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1 http://support.apple.com/kb/HT3438 http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm http://www.debian.org/security/2007/dsa-1294 http://www.mandriva.com/security/advisories?name=MDKSA-2007:079 http://www.mandriva.com/security/advisories?name=MDKSA-2007:080 http://www.novell.com/linux/security/advisories/2007_27_x.html http://www.openbsd.org/errata39.html#021_xorg http://www.openbsd.org/errata40.html#011_xorg http://www.redhat.com/support/errata/RHSA-2007-0126.html http://www.redhat.com/support/errata/RHSA-2007-0132.html http://www.securityfocus.com/archive/1/464686/100/0/threaded http://www.securityfocus.com/archive/1/464816/100/0/threaded http://www.securityfocus.com/bid/23283 http://www.securityfocus.com/bid/23300 http://www.securitytracker.com/id?1017857 http://www.ubuntu.com/usn/usn-448-1 http://www.vupen.com/english/advisories/2007/1217 http://www.vupen.com/english/advisories/2007/1548 https://exchange.xforce.ibmcloud.com/vulnerabilities/33419 https://issues.rpath.com/browse/RPL-1213 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10523 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13243
CVSS v2.0
Source Entity [email protected]
Severity LOW
3.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:A/AC:M/Au:S/C:N/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2007-1352 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:A/AC:M/Au:S/C:N/I:P/A:P

Affected Stack

No specific products linked.