Debian DSA-2838-1 : libxfont - buffer overflow

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote Debian host is missing a security-related update.

Description :

It was discovered that a buffer overflow in the processing of Glyph
Bitmap Distribution fonts (BDF) could result in the execution of
arbitrary code.

See also :

http://www.debian.org/security/2014/dsa-2838

Solution :

Upgrade the libxfont packages.

For the oldstable distribution (squeeze), this problem has been fixed
in version 1:1.4.1-4.

For the stable distribution (wheezy), this problem has been fixed in
version 1:1.4.5-3.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
Public Exploit Available : true

Family: Debian Local Security Checks

Nessus Plugin ID: 71850 ()

Bugtraq ID:

CVE ID: CVE-2013-6462