The vendor explicitly identifies these products as affected by this CVE.
- fontconfig-devel as a component of Red Hat Enterprise Linux 6
- fontconfig.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in fontconfig. This vulnerability, an off-by-one error in how fontconfig handles font capabilities, could allow a local attacker to cause a one-byte out-of-bounds write. This issue may lead to a system crash, resulting in a Denial of Service (DoS), or potentially enable the attacker to execute unauthorized code.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
