Description
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
Affected products
- HP / hp-ux10.24 – 10.24
- HP / hp-ux11.00 – 11.00
- HP / hp-ux11.04 – 11.04
- HP / hp-ux11.11 – 11.11
- HP / hp-ux11.22 – 11.22
- HP / hp-ux10.10 – 10.10
- HP / hp-ux10.20 – 10.20
- sgi / irix6.5.2 – 6.5.2
- sgi / irix6.5.3 – 6.5.3
- sgi / irix6.5.4 – 6.5.4
- sgi / irix6.5.5 – 6.5.5
- sgi / irix6.5.6 – 6.5.6
- sgi / irix6.5.7 – 6.5.7
- sgi / irix6.5.8 – 6.5.8
- sgi / irix6.5.9 – 6.5.9
- sgi / irix6.5.10 – 6.5.10
- sgi / irix6.5.11 – 6.5.11
- sgi / irix6.5.12 – 6.5.12
- sgi / irix6.5.13 – 6.5.13
- sgi / irix6.5 – 6.5
- sgi / irix6.5.1 – 6.5.1
- sun / solaris2.5.1 – 2.5.1
- sun / solaris9.0 – 9.0
- sun / solaris9.0 – 9.0
- sun / solaris8.0 – 8.0
- sun / solaris7.0 – 7.0
- sun / solaris2.5.1 – 2.5.1
- sun / solaris2.6 – 2.6
- sun / sunos5.8 – 5.8
- sun / sunos
- sun / sunos5.5.1 – 5.5.1
- sun / sunos5.7 – 5.7
- xfree86_project / x11r63.3.2 – 3.3.2
- xfree86_project / x11r63.3 – 3.3
- xfree86_project / x11r63.3.5 – 3.3.5
- xfree86_project / x11r63.3.4 – 3.3.4
- xfree86_project / x11r63.3.3 – 3.3.3
References
- VENDOR_ADVISORYhttp://www.securityfocus.com/advisories/4988
- MISChttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/48879
- MAILING_LISThttp://marc.info/?l=bugtraq&m=103825150527843&w=2
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A149
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2002-34.html
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A152
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2816
- MISChttp://www.kb.cert.org/vuls/id/312313
- MISChttp://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21541
- MISChttp://www.iss.net/security_center/static/10375.php
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20021202-01-I
- MISChttp://www.securityfocus.com/bid/6241
- MISChttp://www.ciac.org/ciac/bulletins/n-024.shtml