Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.
| Software | From | Fixed in |
|---|---|---|
| xfree86_project / x11r6 | 4.1.0 | 4.1.0.x |
| xfree86_project / x11r6 | 4.3.0 | 4.3.0.x |
| xfree86_project / x11r6 | 4.2.1 | 4.2.1.x |
| xfree86_project / x11r6 | 4.2.0 | 4.2.0.x |
| xfree86_project / x11r6 | 4.1.12 | 4.1.12.x |
| xfree86_project / x11r6 | 4.1.11 | 4.1.11.x |
| openbsd / openbsd | 3.3 | 3.3.x |
| openbsd / openbsd | 3.4 | 3.4.x |