Impact
A heap buffer overflow in the pcfReadFont() function of libXfont2 occurs when the library parses PCF font files that lack proper glyph bounds checking, a weakness classified as CWE-122 and CWE-787. If an attacker supplies a crafted font file, the overflow can overwrite heap memory and execute arbitrary code with the privileges of the X server process, potentially granting full system compromise.
Affected Systems
The flaw affects any installation of X.Org libXfont2 before version 2.0.8. It applies to all systems running an X11 display server, such as typical Linux or Unix desktop environments and remote X forwarding sessions, where an authenticated X client can provide its own font file to the server.
Risk and Exploitability
Scored with a CVSS of 8.5, the vulnerability poses high severity. The EPSS indicates an exploitation probability below 1%, and the issue is not listed in the CISA KEV catalog, suggesting no widely available exploits at this time. The attack vector requires an authenticated X client, which can be any user logged into a graphical session or a client connected via remote X forwarding. Successful exploitation grants code execution in the X server’s context.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN