Ilja van Sprundel discovered that libXfont incorrectly handled font metadata file parsing. A local attacker could use this issue to cause libXfont to crash, or possibly execute arbitrary code in order to gain privileges. (CVE-2014-0209)
Ilja van Sprundel discovered that libXfont incorrectly handled X Font Server replies. A malicious font server could return specially-crafted data that could cause libXfont to crash, or possibly execute arbitrary code. This issue only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, Ubuntu 12.10 and Ubuntu 13.10. (CVE-2014-0210, CVE-2014-0211)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:1.4.7-1ubuntu0.1", "binary_name": "libxfont-dev" }, { "binary_version": "1:1.4.7-1ubuntu0.1", "binary_name": "libxfont1" }, { "binary_version": "1:1.4.7-1ubuntu0.1", "binary_name": "libxfont1-dbg" }, { "binary_version": "1:1.4.7-1ubuntu0.1", "binary_name": "libxfont1-udeb" } ] }