The vendor explicitly identifies these products or versions as containing the fix.
- libXfont2-0:2.0.3-3.el7_9.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-0:2.0.3-3.el7_9.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-0:2.0.3-3.el7_9.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-0:2.0.3-3.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-0:2.0.3-3.el7_9.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-0:2.0.3-3.el7_9.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-0:2.0.3-3.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-0:2.0.3-3.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-debuginfo-0:2.0.3-3.el7_9.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-debuginfo-0:2.0.3-3.el7_9.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-debuginfo-0:2.0.3-3.el7_9.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- libXfont2-debuginfo-0:2.0.3-3.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- Summary
- A flaw was found in the libXfont2 font-server client. A remote attacker, by operating a malicious font server, could exploit an out-of-bounds read/write vulnerability. This occurs because the client incorrectly handles font data, leading to an out-of-bounds memory access. This can lead to privilege escalation if the X server runs with root privileges, or a denial of service (crash) if it runs as an unprivileged user.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
