CVE-2018-6917

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Unprivileged users may be able to access privileged kernel data.
References
Link Resource
http://www.securityfocus.com/bid/103668 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040629 Third Party Advisory VDB Entry
https://security.FreeBSD.org/advisories/FreeBSD-SA-18:04.vt.asc Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-04 14:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-6917

Mitre link : CVE-2018-6917

CVE.ORG link : CVE-2018-6917


JSON object : View

Products Affected

freebsd

  • freebsd
CWE
CWE-190

Integer Overflow or Wraparound