CVE-2018-6917
04.04.2018, 14:29
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Unprivileged users may be able to access privileged kernel data.Enginsight
| Vendor | Product | Version |
|---|---|---|
| freebsd | freebsd | 10.0 ≤ 𝑥 < 10.4 |
| freebsd | freebsd | 11.0 ≤ 𝑥 < 11.1 |
𝑥
= Vulnerable software versions