Vulnerability Name:

CVE-2003-0730 (CCN-13058)

Assigned:2003-08-30
Published:2003-08-30
Updated:2016-10-18
Summary:Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: NETBSD
Type: UNKNOWN
NetBSD-SA2003-015

Source: SGI
Type: UNKNOWN
20031101-01-U

Source: CCN
Type: BugTraq Mailing List, Sat Aug 30 2003 - 04:25:55 CDT
Multiple integer overflows in XFree86 (local/remote)

Source: MITRE
Type: CNA
CVE-2003-0730

Source: CONECTIVA
Type: UNKNOWN
CLA-2004:821

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2004:821
XFree86

Source: BUGTRAQ
Type: UNKNOWN
20030830 Multiple integer overflows in XFree86 (local/remote)

Source: CCN
Type: RHSA-2003-286
Updated XFree86 packages provide security and bug fixes

Source: CCN
Type: RHSA-2003-287
Updated XFree86 packages provide security and bug fixes

Source: CCN
Type: RHSA-2003-288
Updated XFree86 packages provide security and bug fixes

Source: CCN
Type: RHSA-2003-289
XFree86 security update

Source: CCN
Type: SA24168
Sun Solaris X Font Server / X Render and DBE Extensions Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
24168

Source: CCN
Type: SA24247
Avaya CMS xfs / X Render and DBE Extensions Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
24247

Source: CCN
Type: Sun Alert ID: 102803
Multiple Integer Overflow Vulnerabilities in the X Font Server (xfs(1)) and the X Render and DBE Extensions

Source: SUNALERT
Type: UNKNOWN
102803

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm

Source: CCN
Type: ASA-2007-074
Multiple Integer Overflow Vulnerabilities in the X Font Server (xfs(1)) and the X Render and DBE Extensions (Sun 102803)

Source: CCN
Type: CIAC Information Bulletin O-027
Red Hat Updated XFree86 Packages Provide Security and Bug Fixes

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-380

Source: DEBIAN
Type: DSA-380
xfree86 -- buffer overflows

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2003:089

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2003:286

Source: REDHAT
Type: UNKNOWN
RHSA-2003:287

Source: REDHAT
Type: UNKNOWN
RHSA-2003:288

Source: REDHAT
Type: UNKNOWN
RHSA-2003:289

Source: BID
Type: Patch, Vendor Advisory
8514

Source: CCN
Type: BID-8514
XFree86 Multiple Unspecified Integer Overflow Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2007-0589

Source: CCN
Type: XFree86 Web site
XFree86

Source: XF
Type: UNKNOWN
xfree86-font-integer-overflow(13058)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:xfree86_project:x11r6:4.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:xfree86_project:x11r6:4.3.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:netbsd:netbsd:1.5:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.6:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.6.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:xfree86:xfree86:4.3.0:*:*:*:*:*:*:*
  • AND
  • cpe:/o:freebsd:freebsd:*:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:current:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
  • OR cpe:/o:redhat:linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:aw:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:1.6.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::64bit:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1::itanium:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.1::ppc:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:380
    V
    buffer overflows, denial of service
    2003-09-12
    BACK
    xfree86_project x11r6 4.2.1
    xfree86_project x11r6 4.3.0
    netbsd netbsd 1.5
    netbsd netbsd 1.5.1
    netbsd netbsd 1.5.2
    netbsd netbsd 1.5.3
    netbsd netbsd 1.6
    netbsd netbsd 1.6.1
    xfree86 xfree86 4.3.0
    freebsd freebsd *
    sun solaris 8
    netbsd netbsd 1.5
    redhat linux 7.1
    netbsd netbsd 1.5.1
    redhat linux 7.2
    netbsd netbsd 1.5.2
    conectiva linux 8.0
    redhat linux 7.3
    sun solaris 9
    debian debian linux 3.0
    netbsd netbsd 1.5.3
    netbsd netbsd 1.6
    redhat linux 8.0
    mandrakesoft mandrake linux 9.0
    netbsd netbsd current
    mandrakesoft mandrake linux corporate server 2.1
    mandrakesoft mandrake linux 9.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat linux 9.0
    redhat enterprise linux 2.1
    conectiva linux 9.0
    netbsd netbsd 1.6.1
    sun solaris 10
    redhat linux advanced workstation 2.1
    mandrakesoft mandrake linux 9.1
    mandrakesoft mandrake linux corporate server 2.1