Description: Some vulnerabilities have been reported in XFree86, which can be exploited by malicious, local users to gain escalated privileges.
Integer overflows exist within the "scan_cidfont()" function when handling CMap and CIDFont data, and the "CIDAFM()" function when parsing AFM (Adobe Font Metric) files. These can potentially be exploited to execute arbitrary code via specially crafted CID encoded Type1 fonts.
Successful exploitation may allow to execute arbitrary code with escalated privileges.
Solution: Do not load the "type1" font module.
Provided and/or discovered by: Discovered by an anonymous person and reported via iDEFENSE.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.