Vulnerabilities > CVE-2003-0625 - Off-by-one Error vulnerability in Hadrons Xfstt

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
hadrons
CWE-193
nessus
exploit available

Summary

Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the server's response.

Vulnerable Configurations

Part Description Count
Application
Hadrons
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionxfstt 1.2/1.4 Unspecified Memory Disclosure Vulnerability. CVE-2003-0625 . Dos exploit for linux platform
idEDB-ID:22952
last seen2016-02-02
modified2003-07-23
published2003-07-23
reporterV9
sourcehttps://www.exploit-db.com/download/22952/
titlexfstt 1.2/1.4 Unspecified Memory Disclosure Vulnerability

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-360.NASL
descriptionxfstt, a TrueType font server for the X window system was found to contain two classes of vulnerabilities : CAN-2003-0581: a remote attacker could send requests crafted to trigger any of several buffer overruns, causing a denial of service or possibly executing arbitrary code on the server with the privileges of the
last seen2020-06-01
modified2020-06-02
plugin id15197
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15197
titleDebian DSA-360-1 : xfstt - several vulnerabilities