Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-13720

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cause a buffer over-read during pattern matching of fonts, leading to information disclosure or a crash (denial of service). This occurs because '\0' characters are incorrectly skipped in situations involving ? characters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 9.3%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 3.6
Products affected by CVE-2017-13720
  • X.org » Libxfont » Version: Any
    cpe:2.3:a:x.org:libxfont:*
  • X.org » Libxfont » Version: 2.0.0
    cpe:2.3:a:x.org:libxfont:2.0.0
  • X.org » Libxfont » Version: 2.0.1
    cpe:2.3:a:x.org:libxfont:2.0.1


Contact Us

Shodan ® - All rights reserved