CVE-2007-4568

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/10/2007
Last modified:
09/04/2025

Description

Integer overflow in the build_range function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted size values, which triggers a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:x.org:x_font_server:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:x.org:x_font_server:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:x.org:x_font_server:1.0.4:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools