CVE-2014-0209
Last modified
CVE-2014-0209 is a vulnerability of currently unknown severity. Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X | Libxfont | <= 1.4.7 |
| X | Libxfont | 1.2.3 |
| X | Libxfont | 1.2.4 |
| X | Libxfont | 1.2.5 |
| X | Libxfont | 1.2.6 |
| X | Libxfont | 1.2.7 |
| X | Libxfont | 1.2.8 |
| X | Libxfont | 1.2.9 |
| X | Libxfont | 1.3.0 |
| X | Libxfont | 1.3.1 |
| X | Libxfont | 1.3.2 |
| X | Libxfont | 1.3.3 |
| X | Libxfont | 1.3.4 |
| X | Libxfont | 1.4.0 |
| X | Libxfont | 1.4.1 |
| X | Libxfont | 1.4.2 |
| X | Libxfont | 1.4.3 |
| X | Libxfont | 1.4.4 |
| X | Libxfont | 1.4.5 |
| X | Libxfont | 1.4.6 |
| X | Libxfont | 1.4.99 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 12.10 |
| Canonical | Ubuntu Linux | 13.10 |
| Canonical | Ubuntu Linux | 14.04 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0209?
How severe is CVE-2014-0209?
How do I fix CVE-2014-0209?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-0203The __do_follow_link function in fs/namei.c in the Linux ker…5.5
- CVE-2014-0204OpenStack Identity (Keystone) before 2014.1.1 does not prope…
- CVE-2014-0205The futex_wait function in kernel/futex.c in the Linux kerne…
- CVE-2014-0206Array index error in the aio_read_events_ring function in fs…
- CVE-2014-0207The cdf_read_short_sector function in cdf.c in file before 5…6.5
- CVE-2014-0208Cross-site scripting (XSS) vulnerability in the search auto-…
- CVE-2014-0210Multiple buffer overflows in X.Org libXfont before 1.4.8 and…
- CVE-2014-0211Multiple integer overflows in the (1) fs_get_reply, (2) fs_a…
- CVE-2014-0212qpid-cpp: ACL policies only loaded if the acl-file option sp…7.5
- CVE-2014-0213Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2014-0214login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.1…
- CVE-2014-0215The blind-marking implementation in Moodle through 2.3.11, 2…
Are you affected by CVE-2014-0209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
